Woodgnat Hackers Use Mistic RAT to Broker Access for Ransomware Gangs
2026-06-26T20:51:48Z•6b103088d9351c5b9ca988ebfede9487b0efc2f58607e72cfdb9d4a74785fb22
amadeybrazilbrokerchrome-passwordscredential-theftcrowdstrikedrone-defensefake-alertsghostshellkandjimacosmisticnpmoperation-endgamepostcssransomwareratsocgholishstealcsupply-chainukrainewindows-ratwoodgnatxm-cyberxpc
What happened
Multiple active threats and incidents: the Woodgnat group is deploying the Mistic RAT as a broker tool to sell network access to ransomware gangs; a macOS XPC vulnerability allowed standard users to disable CrowdStrike and Kandji endpoint controls (reported by XM Cyber and since patched); fake GTA 6 “early access” sites and Android/PC lures push malware and crypto scams; malicious npm packages impersonating PostCSS drop a Windows RAT and exfiltrate Chrome passwords; Operation Endgame disrupted StealC, Amadey and SocGholish infrastructure and resulted in mass credential seizures; GhostShell is
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 6b103088d9351c5b9ca988ebfede9487b0efc2f58607e72cfdb9d4a74785fb22
- Enrichment time
- 2026-06-26T20:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.