Also known as: KongTuke, Interlock, Rhysida, Akira, 8Base, tracked as, KongTuk, Bladabindi, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, other ransomware operations, Black Basta, MLTBackdoor, including file download, upload, file manipulation, folder creation, code execution, Bla, Ratenjay, Royal Ransomware
Woodgnat emerged publicly in mid‑2024 as an initial access broker (IAB) that has become a cornerstone in the modern ransomware supply chain. Leveraging sophisticated social engineering—ranging from ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites to Microsoft Teams helpdesk impersonations—the actor entices victims into executing malicious PowerShell commands. These commands deploy its proprietary backdoor families: Backdoor.Mistic (also referred to as Myster or MLTBackdoor) and ModeloRAT. Both RATs employ DLL sideloading via an unsigned, legitimate Microsoft executable (MpExtMs.exe), enabling the malware to blend in with ordinary security tooling (EndpointDlp.dll). Payload execution is exclusively in‑memory, and a self‑delete kill switch ensures rapid removal once its purpose is fulfilled. Woodgnat’s primary operational mode involves purchasing or harvesting compromised systems, installing backdoors for long‑term persistence, and then offering those footholds to ransomware groups. The attacker has been linked with the Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta ransomware families. It additionally sells credential dumps harvested through tools such as Mimikatz, Chisel, Plink or custom credential stealers. Beyond being a broker, Woodgnat demonstrates advanced persistence tactics: registry Run key entries masquerading as legitimate remote‑access utilities (AnyDesk, Splashtop), startup folder shortcuts, VBScript launchers and scheduled tasks. It also performs discovery, credential dumping via Kerberoasting, reflective DLL injection on VMware ESXi, UAC bypass, and employs RC4‑encrypted C2 channels cycling through DGA domains. The actor’s operations are opportunistic but strategically structured to maximize revenue from ransomware affiliates while maintaining a low detection profile.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Woodgnat is a financially motivated initial‑access broker that developed the stealthy Mistic backdoor and ModeloRAT to sell persistence to ransomware operators such as Qilin, Black Basta, and Akira. The group exploits social engineering, compromised WordPress sites, and DLL sideloading via legitimate Microsoft executables to establish in‑memory RATs with a self‑deleting kill switch, then resells the foothold for profit. Its operations span education, insurance, IT, and professional services, making it a key enabler of multi‑stage ransomware campaigns.
Goals & Targeting
Woodgnat’s strategic objectives revolve around monetization through the commercialization of persistent footholds. By providing reliable, stealthy backdoors and credential dumps to multiple ransomware groups, the actor ensures recurring revenue streams without directly deploying destructive payloads. Target selection is opportunistic across sectors that exhibit moderate security maturity—education, insurance, IT services, and professional firms—while exploiting high-value systems such as VMware ESXi hosts or remote‑access infrastructures to maximize payoff for affiliated operators.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Woodgnat operates in a broker model, establishing long‑term remote access across diverse sectors and selling these footholds to ransomware affiliates. Campaigns begin with opportunistic initial access via lures or exploited web vulnerabilities, followed by RAT deployment, credential harvesting, and subsequent hand‑off to an affiliate. The actor’s operational tempo is high velocity; new backdoor releases, such as Mistic in April 2026, appear quickly and may be adapted for additional ransomware families. Victims commonly come from education, insurance, IT, professional services, and increasingly virtualized environments (VMware ESXi). Notable past operations include the sale of access to Qilin, Black Basta, Interlock, Rhysida, Akira, 8Base, and other multi‑stage ransomware campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The aggregation of multiple independent threat intelligence reports, including confirmed sightings of Woodgnat’s backdoors and affiliate associations, affords a moderate to high confidence in the core profile presented. Gaps remain regarding explicit attribution links between Woodgnat and every cited ransomware operation, as well as definitive evidence that all listed tools are directly developed by the actor rather than sourced from shared supply chains.
No campaigns linked yet.
No observed data linked yet.
15
Techniques
50
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics