MLTBackdoor is a newly identified backdoor malware family reported by Zscaler ThreatLabz in May 2026 and assessed as likely being used by a ransomware-related threat actor. It has been observed delivered through a multi-stage ClickFix infection chain that uses fake error messages or fraudulent browser-update style lures to trick victims into copying, pasting, and executing malicious PowerShell or command-line content. In the documented chain, an automotive-themed lure leads to download of an archive from a DGA-generated domain; the archive contains endpointdlp.dll and an RC4-encrypted data.bin payload, and the malware is installed via DLL sideloading using the legitimate Microsoft Defender binary mpextms.exe. After installation, it can self-update and reuse the endpointdlp.dll filename for disguise.
MLTBackdoor is heavily obfuscated and anti-analysis aware. Reported techniques include mixed boolean-arithmetic obfuscation, control-flow flattening, stack-built strings, API hashing, and Hell’s Gate-style indirect system calls; one analysis assessed roughly 95% of the code as unnecessary mathematical operations intended to hinder reverse engineering. It performs ten environment checks covering virtualization, debuggers, analysis tools, sandbox artifacts, low RAM, single-CPU systems, and low uptime, and sends the resulting bitmask to its command-and-control server.
Functionally, MLTBackdoor provides remote access and post-compromise capability including file upload, file download, directory listing, delete, rename, and folder creation. It also includes a Beacon Object File loader that executes BOFs in memory, enabling fileless extension of functionality for post-exploitation activity such as reconnaissance, privilege escalation, and lateral movement. The BOF support includes standard Beacon-style imports and additional BeaconNt* wrappers backed by the malware’s own indirect system call layer.
For command and control, MLTBackdoor uses a custom encrypted binary protocol over TLS/port 443, with reported use of the fixed path /api/v1/telemetry and the User-Agent Microsoft-Delivery-Optimization/10.1 to blend with legitimate traffic. It derives session keys using ECDH on NIST P-256 and encrypts subsequent communications with AES-256-GCM. The malware supports both hardcoded C2 domains and a date-based domain generation algorithm that can produce a new domain daily for resilience.
High-confidence indicators mentioned in the content include the domains hrs2y15sungu.com, carrolc.com, cwrtwright.com, and thomphon.com; the URL powwowski.com/payloads/update.zip; and the SHA-256 hashes 1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984, 46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93, 9e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66, ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7ec, 1d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cf, 2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494, and d34e4038c5c80728f9648ba84833f69bc1ccea82e2e8e748b7b7f02fb687b92b.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Its capabilities include ... executing code received from the command-and-control server directly in memory...
Once an employee falls for the trick, a multi-stage PowerShell chain downloads the malware.
MLTBackdoor is heavily obfuscated using both Mixed Boolean-Arithmetic (MBA) and Control Flow Flattening (CFF) techniques.
Mistic was side-loaded through MpExtMs.exe, a legitimate file, and loaded from a DLL named EndpointDlp.dll, a name associated with Microsoft endpoint-security tooling. This would help the backdoor blend in with trusted software.
If the scammers think they may get caught, they use a built-in kill switch to make the malware delete itself instantly.
When the mission is accomplished, it then terminates and deletes itself.
Inside the downloaded archive are two files: data.bin and endpointdlp.dll. The DLL decrypts the RC4-encrypted data.bin file and unveils the second-stage payload, which is MLTBackdoor itself.
It uses a Microsoft-style user-agent string and a fixed API path to blend in, making it far harder for network monitoring tools to flag any connection as suspicious.
It can also create new folders, and check for additional commands from the attacker-controlled command-and-control (C2) server.
Mistic has all the usual backdoor functionality: It can upload, download, move, rename, and delete files.
the Symantec Threat Hunter Team found Mistic deployed alongside ModeloRAT, a remote access tool tied to attacks involving Qilin, Akira, Rhysida, Black Basta, Interlock, and 8Base.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified backdoor malware family delivered via a multi-stage ClickFix infection chain. It is heavily obfuscated with MBA and CFF, supports filesystem operations, can load Beacon Object Files (BOFs) for in-memory post-exploitation, uses a DGA for C2 resilience, and encrypts communications using ECDH and AES-256-GCM.
A newly identified backdoor used in a multi-stage ClickFix infection chain. It is heavily obfuscated, uses control flow flattening and unnecessary math operations to hinder analysis, employs a DGA to generate daily C2 domains, communicates over port 443 with a custom encrypted binary protocol, performs extensive anti-analysis and sandbox checks, and supports file operations plus in-memory extension through a Beacon Object File loader.
A newly identified backdoor malware family delivered via a multi-stage ClickFix infection chain. It provides remote access, including file upload/download, supports execution of Beacon Object Files (BOFs) for extensibility, and uses obfuscation, anti-analysis techniques, and a Domain Generation Algorithm (DGA) for resilient command-and-control and post-compromise activity.
A backdoor delivered via a ClickFix lure that decrypts and sideloads itself through a legitimate Microsoft Defender executable. It uses heavy LLVM-based obfuscation, API hashing, indirect system calls, anti-analysis checks, a custom TLS-based encrypted C2 protocol, a date-based DGA, built-in file-management commands, and a Beacon Object File loader for post-exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.