New ‘Mistic’ RAT Opens Door to Several Ransomware Families

https://www.securityweek.com/wp-content/uploads/2025/11/malware.jpeg

An initial access broker (IAB) linked to multiple ransomware families has been using a new remote access trojan (RAT) in recent attacks, Broadcom’s Symantec and Carbon Black threat hunter team reports.

The threat actor, tracked as Woodgnat and KongTuke, and active since at least May 2024, is known to have ties to ransomware groups such as Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta.

Starting in April 2026, Woodgnat has been deploying the new Backdoor.Mistic RAT against the networks of organizations across multiple industries, including education, insurance, IT, and professional services.

Previously, the threat actor was observed deploying the ModeloRAT in attacks targeting other entities.

“The targeting appears to be opportunistic, with the attackers casting a wide net and then assessing which organizations they could sell access to rather than focusing on a single sector,” Broadcom’s researchers say.

Also tracked as MLTBackdoor, Mistic provides attackers with typical capabilities, including...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://media.wired.com/photos/6a3bc8bcb0d9ff58f6121983/191:100/w_1280,c_limit/GettyImages-2204326766.jpg

Qualcomm plans to acquire Modular, which builds a chip software platform and has a proprietary coding language, in a nearly $4B deal set to close in H2 2026

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.