Security · 1h ago
New Mistic Backdoor Tied to Ransomware Broker KongTuke
A new backdoor called Mistic has been deployed in financially motivated attacks against insurance, education, IT, and professional services firms. Researchers link the malware to the ransomware access broker KongTuke, known for selling network access to ransomware groups. The backdoor uses stealthy techniques to evade detection and maintain persistence on compromised systems.
Meridian48 take
While Mistic is not groundbreaking, its connection to a known access broker underscores the ongoing commoditization of ransomware tools.
Read the full reporting
Stealthy Mistic backdoor linked to ransomware access broker KongTuke →
Bleeping Computer
mistic-backdoorkongtuke