← All stories
● Covered by 1 source · 1 reportHigh impact

New Mistic Backdoor Discovered Linked to KongTuke in Cyber Attack Campaigns

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Mistic backdoor linked to KongTuke and used in financial attacks
  • Operates in memory with features for stealth and self-deletion
  • Employs DLL side-loading for evasion and access to systems

Overview of Mistic Backdoor

The Mistic backdoor, also referred to as MLTBackdoor, was first identified in attacks targeting multiple industries including insurance, education, IT, and professional services. Reports indicate that it has been active since April 2026 and is associated with the financial threat group KongTuke. This connection highlights a shift towards sophisticated cybercrime tactics aimed at wide-ranging sectors.

Technical Details

Mistic is notable for operating in memory without writing files to disk, making it difficult to detect. Its implementation includes a self-destruct feature, allowing it to eliminate traces of its presence if detected. The malware can upload, download, move, rename, and delete files, among other functionalities.

Delivery and Methodology

The deployment of Mistic is linked to a broader campaign utilizing ClickFix as a delivery vector, with malicious Google Chrome extensions and DNS for staging additional payloads. These tactics have been connected to the ModeloRAT, which expands the capabilities of Mistic, ensuring a persistent foothold in targeted systems.

Implications for Cybersecurity

The emergence of the Mistic backdoor and its sophisticated operational methods poses a high-level threat, particularly due to its stealth and connection to financially motivated attacks. Organizations in susceptible sectors need to enhance their cybersecurity measures to defend against such advanced persistent threats.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new backdoor named Mistic has emerged in attacks directed at various sectors, linked to the KongTuke group. The stealthy malware is designed for long-term access, employing sophisticated evasion techniques such as memory-based execution and DLL side-loading, marking a significant threat to targeted organizations.