New ‘Mistic’ RAT Opens Door to Several Ransomware Families
An initial access broker (IAB) linked to multiple ransomware families has been using a new remote access trojan (RAT) in recent attacks, Broadcom’s Symantec and Carbon Black threat hunter team reports.
The threat actor, tracked as Woodgnat and KongTuke, and active since at least May 2024, is known to have ties to ransomware groups such as Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta.
Starting in April 2026, Woodgnat has been deploying the new Backdoor.Mistic RAT against the networks of organizations across multiple industries, including education, insurance, IT, and professional services.
Previously, the threat actor was observed deploying the ModeloRAT in attacks targeting other entities.
“The targeting appears to be opportunistic, with the attackers casting a wide net and then assessing which organizations they could sell access to rather than focusing on a single sector,” Broadcom’s researchers say.
Also tracked as MLTBackdoor, Mistic provides attackers with typical capabilities, including...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE