Stealthy new backdoor surfaces in attacks on multiple sectors

2026-06-25T14:51:44Zbd0942df1599b979b7555d71f0c07a7d12f96dce6757f4367e8eb2fd0f326002
8BaseAkiraBlack BastaIABInterlockKongTukeMisticQilinRhysidaSymantecWoodgnatbackdooreducationinformation-technologyinitial access brokerinsurancemalwareprofessional-servicesransomwaresector-targeting

What happened

Symantec reports a stealthy backdoor named Mistic has been deployed since April 2026 against organizations in insurance, education, IT and professional services. Mistic is linked to Woodgnat (aka KongTuke), a financially motivated initial access broker active since at least May 2024 that has been associated with multiple ransomware operations (Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta). The actor likely provides access for downstream ransomware affiliates, making these intrusions a high-risk vector for disruptive extortion activity.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
bd0942df1599b979b7555d71f0c07a7d12f96dce6757f4367e8eb2fd0f326002
Enrichment time
2026-06-25T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.