Woodgnat Hackers Use Mistic RAT to Broker Access for Ransomware Gangs

2026-06-26T20:51:48Z6b103088d9351c5b9ca988ebfede9487b0efc2f58607e72cfdb9d4a74785fb22
amadeybrazilbrokerchrome-passwordscredential-theftcrowdstrikedrone-defensefake-alertsghostshellkandjimacosmisticnpmoperation-endgamepostcssransomwareratsocgholishstealcsupply-chainukrainewindows-ratwoodgnatxm-cyberxpc

What happened

Multiple active threats and incidents: the Woodgnat group is deploying the Mistic RAT as a broker tool to sell network access to ransomware gangs; a macOS XPC vulnerability allowed standard users to disable CrowdStrike and Kandji endpoint controls (reported by XM Cyber and since patched); fake GTA 6 “early access” sites and Android/PC lures push malware and crypto scams; malicious npm packages impersonating PostCSS drop a Windows RAT and exfiltrate Chrome passwords; Operation Endgame disrupted StealC, Amadey and SocGholish infrastructure and resulted in mass credential seizures; GhostShell is

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
6b103088d9351c5b9ca988ebfede9487b0efc2f58607e72cfdb9d4a74785fb22
Enrichment time
2026-06-26T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Woodgnat Hackers Use Mistic RAT to Broker Access for Ransomware Gangs · Baitaphish