Woodgnat, publicly known as KongTuke, is a financially motivated cybercrime operation active since at least May 2024. It functions primarily as an initial access broker, compromising enterprise environments, profiling their value, establishing durable access, and selling that access to ransomware affiliates and other criminal actors. Woodgnat has been linked to ransomware ecosystems including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Woodgnat conducts opportunistic intrusions affecting insurance, education, information-technology, and professional-services organizations. It uses compromised WordPress sites and injected JavaScript to deliver social-engineering lures, including ClickFix, FileFix, and CrashFix variants, that persuade victims to execute attacker-supplied commands. Since April 2026, it has also used Microsoft Teams helpdesk and IT-support impersonation pretexts to induce PowerShell execution. The actor is associated with ModeloRAT, a Python-based remote-access trojan, and with intrusion activity involving the Mistic backdoor, also tracked as MLTBackdoor. Mistic supports remote file operations, in-memory code execution, configurable beaconing, and self-removal. Observed campaigns have employed DLL sideloading, memory-only execution, credential harvesting through fake login prompts, and legitimate Windows utilities for reconnaissance, command execution, registry manipulation, lateral movement, and data transfer. Woodgnat's use of stealth-oriented tooling and access resale positions it upstream in ransomware intrusion chains rather than as a confirmed ransomware operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
43 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An initial-access broker believed to have developed ModeloRAT and linked to ransomware-family activity.
Financially motivated initial access broker operations targeting enterprise environments, establishing footholds and selling access to ransomware affiliates. The group is linked in this content to Mistic intrusions using social engineering lures, compromised WordPress sites, fake browser crashes, fake CAPTCHA pages, FileFix/CrashFix-style prompts, and fake Microsoft Teams helpdesk chats.
Identified as an initial access broker suspected of being linked to Backdoor.Mistic activity.
Initial access broker activity using Backdoor.Mistic and ModeloRAT to infiltrate corporate networks and sell access to ransomware operators.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.