Stealthy new backdoor surfaces in attacks on multiple sectors
2026-06-25T14:51:44Z•bd0942df1599b979b7555d71f0c07a7d12f96dce6757f4367e8eb2fd0f326002
8BaseAkiraBlack BastaIABInterlockKongTukeMisticQilinRhysidaSymantecWoodgnatbackdooreducationinformation-technologyinitial access brokerinsurancemalwareprofessional-servicesransomwaresector-targeting
What happened
Symantec reports a stealthy backdoor named Mistic has been deployed since April 2026 against organizations in insurance, education, IT and professional services. Mistic is linked to Woodgnat (aka KongTuke), a financially motivated initial access broker active since at least May 2024 that has been associated with multiple ransomware operations (Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta). The actor likely provides access for downstream ransomware affiliates, making these intrusions a high-risk vector for disruptive extortion activity.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- bd0942df1599b979b7555d71f0c07a7d12f96dce6757f4367e8eb2fd0f326002
- Enrichment time
- 2026-06-25T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.