Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors woodgnat

Also known as: KongTuke, Interlock, Rhysida, Akira, 8Base, tracked as, KongTuk, Bladabindi, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, other ransomware operations, Black Basta, MLTBackdoor, including file download, upload, file manipulation, folder creation, code execution, Bla, Ratenjay, Royal Ransomware

Description

Woodgnat emerged publicly in mid‑2024 as an initial access broker (IAB) that has become a cornerstone in the modern ransomware supply chain. Leveraging sophisticated social engineering—ranging from ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites to Microsoft Teams helpdesk impersonations—the actor entices victims into executing malicious PowerShell commands. These commands deploy its proprietary backdoor families: Backdoor.Mistic (also referred to as Myster or MLTBackdoor) and ModeloRAT. Both RATs employ DLL sideloading via an unsigned, legitimate Microsoft executable (MpExtMs.exe), enabling the malware to blend in with ordinary security tooling (EndpointDlp.dll). Payload execution is exclusively in‑memory, and a self‑delete kill switch ensures rapid removal once its purpose is fulfilled. Woodgnat’s primary operational mode involves purchasing or harvesting compromised systems, installing backdoors for long‑term persistence, and then offering those footholds to ransomware groups. The attacker has been linked with the Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta ransomware families. It additionally sells credential dumps harvested through tools such as Mimikatz, Chisel, Plink or custom credential stealers. Beyond being a broker, Woodgnat demonstrates advanced persistence tactics: registry Run key entries masquerading as legitimate remote‑access utilities (AnyDesk, Splashtop), startup folder shortcuts, VBScript launchers and scheduled tasks. It also performs discovery, credential dumping via Kerberoasting, reflective DLL injection on VMware ESXi, UAC bypass, and employs RC4‑encrypted C2 channels cycling through DGA domains. The actor’s operations are opportunistic but strategically structured to maximize revenue from ransomware affiliates while maintaining a low detection profile.

Goals & Targeting

Targeted Sectors

Education
Financial services
Government
Telecommunications
Defense
Healthcare
Critical infrastructure
Media
Manufacturing
Retail
Aerospace
Non profit
Information technology
Hospitality
Aviation
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation

Targeted Countries / Regions

CN
RU
IN
UA
GB
DE
KP
IR
BR
PK
BY
PL
TW
CA
AU
JP

AI Analysis

Grounded in web research
· analyzed in 38 chunks · 6 days ago

Executive Summary

Woodgnat is a financially motivated initial‑access broker that developed the stealthy Mistic backdoor and ModeloRAT to sell persistence to ransomware operators such as Qilin, Black Basta, and Akira. The group exploits social engineering, compromised WordPress sites, and DLL sideloading via legitimate Microsoft executables to establish in‑memory RATs with a self‑deleting kill switch, then resells the foothold for profit. Its operations span education, insurance, IT, and professional services, making it a key enabler of multi‑stage ransomware campaigns.

Goals & Targeting

Woodgnat’s strategic objectives revolve around monetization through the commercialization of persistent footholds. By providing reliable, stealthy backdoors and credential dumps to multiple ransomware groups, the actor ensures recurring revenue streams without directly deploying destructive payloads. Target selection is opportunistic across sectors that exhibit moderate security maturity—education, insurance, IT services, and professional firms—while exploiting high-value systems such as VMware ESXi hosts or remote‑access infrastructures to maximize payoff for affiliated operators.

Enhanced Description

Key Capabilities

  • initial access brokerage
  • remote access via RATs (Mistic, ModeloRAT)
  • DLL sideloading through legitimate Microsoft executables
  • in‑memory execution with no disk persistence
  • self‑delete kill switch for stealth
  • credential dumping using Mimikatz and custom stealers
  • delivery of malicious lures (ClickFix, FileFix, CrashFix) via compromised WordPress sites
  • social engineering including fake CAPTCHAs and Teams helpdesk impersonation
  • extensive discovery and reconnaissance (Kerberoasting, PowerShell enumeration)
  • lateral movement via RDP and reflective DLL injection on ESXi
  • use of RC4‑encrypted DGA-based C2 channels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Exfiltration
Impact
Command and Control
Privilege Escalation
Lateral Movement
Reconnaissance
Discovery

ATT&CK Techniques

T1055.004
T1070.001
T1059.001
T1566.001
T1566.002
T1003.001
T1071.003
T1041
T1485
T1190
T1185
T1486
T1048
T1567
T1078
T1076
T1189
T1064
T1053
T1490
T1110
T1136
T1086
T1204
T1059
T1105
T1071
T1218
T1056
T1047
T1112
T1547.001
T1087
T1069
T1036
T1027
T1558.004
T1021

Software / Tooling

Backdoor.Mistic
ModeloRAT
ClickFix
FileFix
CrashFix
KongTuke
SnailResin
SlugResin
Mimikatz
Chisel
Plink
PowerShell
GootLoader
Cobalt Strike
AnyDesk
CloudChat
GCollection
DWP
AnvilEcho
TAMECAT
CharmPower
PINEFLOWER
RClone

Campaigns & Victims

Woodgnat operates in a broker model, establishing long‑term remote access across diverse sectors and selling these footholds to ransomware affiliates. Campaigns begin with opportunistic initial access via lures or exploited web vulnerabilities, followed by RAT deployment, credential harvesting, and subsequent hand‑off to an affiliate. The actor’s operational tempo is high velocity; new backdoor releases, such as Mistic in April 2026, appear quickly and may be adapted for additional ransomware families. Victims commonly come from education, insurance, IT, professional services, and increasingly virtualized environments (VMware ESXi). Notable past operations include the sale of access to Qilin, Black Basta, Interlock, Rhysida, Akira, 8Base, and other multi‑stage ransomware campaigns.

IOC Patterns

  • stealth backdoor
  • DLL sideloading via legitimate Microsoft executable
  • in-memory execution
  • self-deleting kill switch
  • malicious PowerShell command delivery
  • ClickFix/ FileFix / CrashFix lures
  • credential dumping via Mimikatz
  • RC4-encrypted DGA C2 channels
  • watering‑hole compromised WordPress sites
  • fake Teams helpdesk messages
  • spear-phishing with macro-enabled Office documents
  • DNS tunneling

Recommended Actions

  • Deploy endpoint detection and response rules for Backdoor.Mistic, ModeloRAT, and KongTuke signatures.
  • Block known lure domains (ClickFix, FileFix, CrashFix) at the perimeter and in email filtering solutions.
  • Implement application whitelisting to prevent DLL sideloading of EndpointDlp.dll via MpExtMs.exe.
  • Enforce strict least‑privilege and MFA for remote access services such as VPN and RDP.
  • Monitor PowerShell activity for suspicious cmdlet patterns (download, base64 encoded scripts).
  • Detect self-deleting processes and file deletion events indicative of kill switches.
  • Configure network segmentation to isolate ESXi hosts from corporate LANs.
  • Set up outbound TLS inspection or anomaly detection for RC4‑encrypted HTTP traffic to unknown domains.
  • Conduct regular vulnerability scans against public-facing WordPress installations and patch promptly.
  • Provide user awareness training focused on malicious lures, fake CAPTCHAs, and Teams impersonations.

Suggested Tags

initial-access-broker
stealth-backdoor
remote-access-trojan
ransomware-brokerage
DLL-sideloading
in-memory-execution
credential-dumping
malicious-lure
watering-hole
social-engineering
PowerShell-abuse
RDP-lateralmovement
ESXi-targets

Confidence Assessment

The aggregation of multiple independent threat intelligence reports, including confirmed sightings of Woodgnat’s backdoors and affiliate associations, affords a moderate to high confidence in the core profile presented. Gaps remain regarding explicit attribution links between Woodgnat and every cited ransomware operation, as well as definitive evidence that all listed tools are directly developed by the actor rather than sourced from shared supply chains.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

15

Techniques

50

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

initial-access-broker
stealth-backdoor
remote-access-trojan
ransomware-brokerage
DLL-sideloading
in-memory-execution
credential-dumping
malicious-lure
watering-hole
social-engineering
PowerShell-abuse
RDP-lateralmovement
ESXi-targets

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.