Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators New Backdoor May be Linked to Ransomware Access Broker

f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e

TLP:CLEAR
Active

SHA-256 Hash

Description

A stealthy new backdoor called Mistic has been deployed in cybercrime intrusions since April 2026, potentially linked to Woodgnat, an initial access broker associated with multiple ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta. Mistic was deployed alongside ModeloRAT in at least one case, a tool developed by Woodgnat. The backdoor uses sideloading techniques through legitimate Microsoft files and executes payloads in memory without writing to disk. It includes typical backdoor capabilities plus a self-delete kill switch for enhanced stealth. Targeting appears opportunistic across insurance, education, IT and professional services sectors. Woodgnat operates as an IAB, establishing durable remote access within enterprises and selling this access to ransomware affiliates, using various social-engineering techniques including ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites.

Sightings (0)

No sightings recorded yet

Details

Name / Label
New Backdoor May be Linked to Ransomware Access Broker
Pattern Type
STIX
Confidence
75%
Valid From
Jul 24, 2026 20:07
Total Sightings
0
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.