Mistic, also tracked as MLTBackdoor, is a Windows remote-access backdoor used in financially motivated enterprise intrusions since April 2026. It has targeted organizations in the insurance, education, information technology, and professional-services sectors. Mistic is designed for stealthy, durable access: it receives command-and-control tasking, supports file upload, download, deletion, movement, renaming, and folder creation, can adjust its check-in interval, and executes operator-supplied code directly in memory. It can also load Beacon Object Files to extend post-exploitation functionality without relying on disk artifacts. A built-in kill switch enables operators to terminate and remove the implant, reducing forensic evidence. Mistic has been deployed through DLL sideloading involving trusted Microsoft endpoint-security software, and has been observed in ClickFix-based infection chains that induce victims to execute malicious PowerShell commands. Related intrusions included a separate fake-login credential-stealing component and ModeloRAT. Activity involving Mistic is assessed as associated with the financially motivated initial-access broker KongTuke, also known as Woodgnat, whose operations seek opportunistic enterprise footholds that may be sold to ransomware affiliates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The technique was employed alongside ModeloRAT and Mistic (aka MLTBackdoor); the report later calls it Backdoor.Mistic.
The technique was employed alongside ModeloRAT and Mistic (aka MLTBackdoor); the report later calls it Backdoor.Mistic.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Additional tools seen in the same attack chains included PowerShell, certutil, WMIC, and curl.exe, all legitimate Windows utilities repurposed for malicious activity.
Once loaded, Mistic connects to its command-and-control server and waits for instructions... run code directly in memory
Woodgnat attack chains abuse node.exe to execute attacker JavaScript and chain PowerShell and Windows command-line tools.
Woodgnat attack chains abuse node.exe to execute attacker JavaScript and chain PowerShell and Windows command-line tools.
The malicious DLL is named EndpointDlp.dll, borrowing the name from a genuine Microsoft endpoint security component, helping it blend seamlessly into trusted software environments.
The backdoor runs payloads in memory with no file written to disk... Zscaler researchers say that 'one of the most powerful features [in MTLBackdoor] is the ability to load Beacon Object Files (BOFs) to expand its capabilities.'
Its capabilities include ... terminating and removing itself from an infected system.
When the mission is accomplished, it then terminates and deletes itself.
The group typically gains a foothold by compromising WordPress websites through vulnerable plugins or stolen credentials
a legitimate Microsoft executable named MpExtMs.exe is manipulated into loading a malicious file instead of the expected one.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor associated with KongTuke/Woodgnat campaigns that abuse node.exe to execute attacker-controlled JavaScript and chain PowerShell and Windows command-line tooling.
Mentioned only as a comparison relating to memory-execution detection and monitoring.
Referenced as a backdoor/access tool in a comparison about ransomware-access response principles.
A previously unknown backdoor deployed via the ClickFix initial access technique by KongTuke, enabling downstream compromises including by Qilin affiliates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.