Mistic is a Windows backdoor used in financially motivated enterprise intrusions since at least April 2026. It has been associated with activity linked to the initial access broker Woodgnat, also known as KongTuke, an actor known for obtaining footholds in corporate environments and selling that access to ransomware affiliates including Qilin, Akira, Rhysida, Black Basta, Interlock, and 8Base. Reported targeting has included organizations in the insurance, education, information technology, and professional services sectors, with victim selection assessed as largely opportunistic.
Mistic is designed for stealth and durable access. It is commonly deployed through DLL sideloading using a legitimate Microsoft executable to load a malicious DLL that masquerades as Microsoft endpoint security tooling. The malware executes operator-supplied code directly in memory, reducing disk artifacts and complicating file-based detection. Observed functionality includes command-and-control beaconing, configurable check-in intervals, file upload and download, file and folder manipulation, and self-removal through a built-in kill switch intended to reduce forensic evidence. Some reporting also notes support for loading Beacon Object Files to extend post-exploitation capability in memory.
Mistic has appeared in intrusion chains that also involved ModeloRAT and a separate credential-stealing component that presented a fake login screen to harvest usernames and passwords. Related campaigns used social-engineering lures associated with Woodgnat tradecraft, including fake browser crash prompts, fake CAPTCHA checks, ClickFix-style command execution, and fake Microsoft Teams helpdesk interactions that trick victims into running attacker-supplied PowerShell commands. Operators in the same intrusions also abused legitimate Windows utilities for reconnaissance, persistence, credential theft, lateral movement, and post-compromise activity. Overall, Mistic appears to function as a stealthy access-maintenance tool within an initial-access-broker ecosystem rather than as ransomware itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KongTuke, for example, used this technique to plant a previously unknown backdoor called Mistic on opportunistically selected target systems, which led, among other things, to compromises by Qilin affiliates.
A newly identified Windows backdoor called Mistic has been quietly making its way through enterprise networks since April 2026, giving attackers persistent, low-profile access that is extremely difficult to detect.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Additional tools seen in the same attack chains included PowerShell, certutil, WMIC, and curl.exe, all legitimate Windows utilities repurposed for malicious activity.
Once loaded, Mistic connects to its command-and-control server and waits for instructions... run code directly in memory
attackers used social engineering lures, including fake browser crashes and fake CAPTCHA tests, to trick victims into executing attacker-supplied PowerShell commands.
Woodgnat has refined these lures, shifting from ClickFix fake error pages to FileFix and then CrashFix techniques, all designed to push victims into pasting and running attacker-supplied commands.
KongTuke has been known to use ClickFix, and its FileFix and CrashFix variants, since early 2025 to deliver the ModeloRAT malware. In a technical report this week, Zscaler notes that Mistic, which it tracks as MTLBackdoor, was delivered as a payload in a multi-stage ClickFix infection chain in May.
The malicious DLL is named EndpointDlp.dll, borrowing the name from a genuine Microsoft endpoint security component, helping it blend seamlessly into trusted software environments.
The backdoor runs payloads in memory with no file written to disk... Zscaler researchers say that 'one of the most powerful features [in MTLBackdoor] is the ability to load Beacon Object Files (BOFs) to expand its capabilities.'
Its capabilities include ... terminating and removing itself from an infected system.
When the mission is accomplished, it then terminates and deletes itself.
The group typically gains a foothold by compromising WordPress websites through vulnerable plugins or stolen credentials
a legitimate Microsoft executable named MpExtMs.exe is manipulated into loading a malicious file instead of the expected one.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a backdoor/access tool in a comparison about ransomware-access response principles.
A previously unknown backdoor deployed via the ClickFix initial access technique by KongTuke, enabling downstream compromises including by Qilin affiliates.
Named as another malware family distributed via ClickFix in the broader threat landscape.
A Windows backdoor that uses DLL sideloading and in-memory execution to maintain stealthy persistence, communicate with C2 infrastructure, transfer files, manipulate folders, execute operator-supplied code directly in memory, and remove itself via a kill switch.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.