Mistic is a Windows backdoor active since at least April 2026 in financially motivated enterprise intrusions. It has been observed targeting organizations in the insurance, education, information technology, and professional services sectors and is assessed to be associated with the initial access broker Woodgnat, also known as KongTuke. That actor is known for obtaining footholds in corporate environments and selling access to ransomware affiliates, including operators associated with Qilin, Akira, Rhysida, Black Basta, Interlock, and 8Base.
Mistic is designed for stealthy, durable access. It is commonly deployed through DLL sideloading using a legitimate Microsoft executable and a malicious DLL named to resemble Microsoft endpoint security components. The malware executes operator-supplied code directly in memory, reducing disk artifacts and complicating file-based detection. Reported functionality includes command-and-control communications, configurable beaconing, file upload and download, file and folder manipulation, and self-removal through a built-in kill switch intended to reduce forensic evidence.
Observed intrusion chains linked to Mistic also included social-engineering-driven execution of attacker-supplied PowerShell commands, including fake CAPTCHA, fake browser crash, and fake Microsoft Teams helpdesk lures consistent with Woodgnat tradecraft. In some cases Mistic appeared alongside ModeloRAT and a separate credential-stealing component that presented a fake login screen. The malware’s role is consistent with access-broker operations focused on establishing persistent, low-visibility access that can later support ransomware deployment, lateral movement, and broader post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KongTuke, for example, used this technique to plant a previously unknown backdoor called Mistic on opportunistically selected target systems, which led, among other things, to compromises by Qilin affiliates.
A newly identified Windows backdoor called Mistic has been quietly making its way through enterprise networks since April 2026, giving attackers persistent, low-profile access that is extremely difficult to detect.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Additional tools seen in the same attack chains included PowerShell, certutil, WMIC, and curl.exe, all legitimate Windows utilities repurposed for malicious activity.
Once loaded, Mistic connects to its command-and-control server and waits for instructions... run code directly in memory
attackers used social engineering lures, including fake browser crashes and fake CAPTCHA tests, to trick victims into executing attacker-supplied PowerShell commands.
Woodgnat has refined these lures, shifting from ClickFix fake error pages to FileFix and then CrashFix techniques, all designed to push victims into pasting and running attacker-supplied commands.
KongTuke has been known to use ClickFix, and its FileFix and CrashFix variants, since early 2025 to deliver the ModeloRAT malware. In a technical report this week, Zscaler notes that Mistic, which it tracks as MTLBackdoor, was delivered as a payload in a multi-stage ClickFix infection chain in May.
The malicious DLL is named EndpointDlp.dll, borrowing the name from a genuine Microsoft endpoint security component, helping it blend seamlessly into trusted software environments.
The backdoor runs payloads in memory with no file written to disk... Zscaler researchers say that 'one of the most powerful features [in MTLBackdoor] is the ability to load Beacon Object Files (BOFs) to expand its capabilities.'
Its capabilities include ... terminating and removing itself from an infected system.
When the mission is accomplished, it then terminates and deletes itself.
The group typically gains a foothold by compromising WordPress websites through vulnerable plugins or stolen credentials
a legitimate Microsoft executable named MpExtMs.exe is manipulated into loading a malicious file instead of the expected one.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously unknown backdoor deployed via the ClickFix initial access technique by KongTuke, enabling downstream compromises including by Qilin affiliates.
Named as another malware family distributed via ClickFix in the broader threat landscape.
A Windows backdoor that uses DLL sideloading and in-memory execution to maintain stealthy persistence, communicate with C2 infrastructure, transfer files, manipulate folders, execute operator-supplied code directly in memory, and remove itself via a kill switch.
A stealthy backdoor used for long-term covert access. It communicates with a C2 server, can upload/download/move/rename/delete files, create folders, adjust beacon intervals, execute payloads in memory without writing to disk, and remove itself via a kill switch. It was observed delivered via DLL sideloading using the legitimate MpExtMs.exe process and a malicious DLL named EndpointDlp.dll.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.