Symantec Links a Self-Destructing 'Mistic' Backdoor to the KongTuke Access Broker Feeding Six Ransomware Crews
Symantec ties the in-memory Mistic backdoor to access broker KongTuke, whose footholds have fed Qilin, Akira, Black Basta and other ransomware groups since April 2026.
Overview
Symantec’s Threat Hunter Team has documented a new in-memory backdoor it calls Backdoor.Mistic and linked it to a financially motivated initial access broker, according to Symantec. The broker, tracked publicly as KongTuke and as Woodgnat by Symantec, has been active as an initial access broker since at least May 2024, Help Net Security reported. The same malware family was first documented earlier this month by Zscaler, which tracks it as MLTBackdoor, according to Symantec.
The significance is less the individual tool than the business model behind it. KongTuke does not run ransomware itself; it sells durable footholds inside corporate networks to ransomware affiliates. As reported by SecurityWeek, the access it brokers has shown up ahead of attacks by Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
What We Know
Symantec says the broker has been deploying the new backdoor since April 2026, according to SecurityWeek. The targeting has been opportunistic and spread across multiple sectors, including insurance, education, IT, and professional services, Symantec reported.
Mistic is built for stealth. According to Help Net Security, its capabilities include uploading, downloading, moving, renaming, and deleting files, creating folders, modifying how frequently it checks for commands, executing code received from the command-and-control server directly in memory, and terminating and removing itself. The combination of in-memory execution and a built-in kill switch makes it stealthy and potentially capable of long-term access, Help Net Security noted. Security Affairs similarly described a backdoor that runs payloads in memory with no file written to disk and includes a kill switch that lets it delete itself.
The delivery mechanism leans on the appearance of legitimate security software. According to Symantec, Mistic was side-loaded through MpExtMs.exe, a legitimate file, and loaded from a DLL named EndpointDlp.dll, a name associated with Microsoft endpoint-security tooling. The same sideloading chain was described by Security Affairs.
Mistic is not the broker’s only custom tool. The actor also operates ModeloRAT, a Python-based remote access trojan it developed, according to Help Net Security. Symantec observed ModeloRAT in attacks that deployed Qilin ransomware, Symantec reported.
Across these intrusions, the operators have relied heavily on living-off-the-land binaries. SecurityWeek reported the use of Curl, Reg.exe, Net (net.exe), PowerShell, Certutil, and WMIC, and noted that since April 2026 the actor has paired ClickFix, FileFix, and CrashFix techniques with helpdesk and IT-support lures delivered via Microsoft Teams.
What We Don’t Know
The public reporting does not name the specific victim organizations or quantify how many networks the broker has compromised. Because Mistic executes in memory and can erase itself, the full scope of intrusions where it was used may be difficult to reconstruct from forensic evidence. The reporting also stops short of a definitive, named-actor attribution beyond the KongTuke/Woodgnat tracking handles, and it does not establish which ransomware deployments were the direct result of Mistic specifically rather than the broker’s other tooling.
Analysis
The Mistic disclosure is a window into the division of labor that now defines much of the ransomware economy. Initial access brokers like KongTuke specialize in one job — getting in and staying in quietly — then monetize that access by selling it onward, leaving the noisy work of encryption and extortion to affiliates. A stealthy, self-deleting, memory-resident implant is well suited to that role: it is meant to persist long enough to be sold, not to be found. The breadth of downstream ransomware families tied to the broker’s access, from Qilin and Akira to Black Basta, underscores why disrupting the broker layer can matter more than chasing any single ransomware brand.