Symantec Links a Self-Destructing 'Mistic' Backdoor to the KongTuke Access Broker Feeding Six Ransomware Crews
Symantec ties the in-memory Mistic backdoor to access broker KongTuke, whose footholds have fed Qilin, Akira, Black Basta and other ransomware groups since April 2026.