Although the information regarding these events is based upon publicly available sources and may have changed since the date of publication, the following represents a summary of what we currently know:
In April 2026, researchers with Symantec and Carbon Black's Threat Hunter Team discovered that a backdoor called "Mistic" had been installed within several organizations operating within the Insurance, Education, Technology, and Professional Services industries. This backdoor is also identified as "MLTBackdoor." It was discovered that the backdoor was connected to an Initial Access Broker (IAB) called "KongTuke" (also referred to as "404 TDS," "Chaya_002," "LandUpdate808," "TAG-124," "Woodgnat"), and was deployed concurrently with ModeloRAT, a Python Remote Access Trojan (RAT).
"The backdoor executes payloads in-memory with no files written to disk, and includes a 'killswitch' that allows it to remove itself. These characteristics align with an attacker seeking to maintain long-term visibility and a minimal footprint."
Broadcom Cybersecurity teams reported on the discovery of ModeloRAT, stating that it was first identified by Huntress in January 2026 in relation to a version of a ClickFix campaign titled Crash Fix. In Crash Fix, the KongTuke actors utilised a malicious Google Chrome extension, presented as an advertisement-blocking application, to intentionally cause a victim's web browser to fail and prompt them to run arbitrary command-line applications under the guise of conducting a security audit.
This malware was delivered through a second ClickFix campaign where Microsoft stated that the attack chain utilises DNS as a lightweight staging or signalling channel.
Zscaler Threat Labs published an analysis of Mistic in early July 2026, highlighting how Mistic utilised ClickFix to deliver the malware. According to their research, the malware was being operated by a threat actor attempting to create a foothold for lateral movement related to ransomware.
Additional findings from Broadcom reveal that Mistic operates using DLL sideloading techniques. Specifically, Mistic utilises trusted Microsoft Endpoint Security tooling ("MpExtMs.exe") to mask itself and prevent alerts. Additionally, Mistic is designed to execute directly in memory. Therefore, it can perform all typical actions of malware families of this type, such as:
- Upload/Download a file
- Move/Rename/Delete a file
- Create a folder
- Modify time interval between polls of remote server commands
- Execute code received from Command & Control center in memory without creating disk artifacts
- Load Beacon Object Files (BOF) to dynamically expand capabilities
- Delete/Terminate self
"Targeted attack appears to be opportunistic in nature and the attackers appear to cast a large net and then determine which organisations they can resell access to, versus focusing on one specific industry vertical." Symantec and Carbon Black further explained that ModeloRAT has been observed in attacks involving Qilin ransomware.
It is well-documented that KongTuke operates a Traffic Distribution System (TDS) utilising compromised WordPress sites as a means to host a dynamic array of lures that direct unwitting visitors to malware. Most notably, in June 2026, Rapid7 and ReliaQuest disclosed that KongTuke has transitioned their tactics to send Microsoft Teams messages from a fake IT support account as a method to initiate an attack chain leading to deployment of ModeloRAT.
"The stealthiness of the backdoor is also noteworthy. Woodgnat may also be responsible for development of ModeloRAT, which would suggest that the group developing these tools has high levels of expertise relative to the design of stealthy remote access tools."
"Custom tool usage in ransomware attacks is increasingly becoming more commonplace. There are many instances of ransomware groups leveraging custom exfiltration tools, among others, during ransomware campaigns. Backdoor.Mistic appears to be another example of this trend. However, it seems most likely that it was created by access brokers working on behalf of ransomware affiliates instead of a ransomware group itself."