threat-intel
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
High
Summary
A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional services sectors. The backdoor, developed with features designed for long-term persistence, has been linked to several ransomware groups including Qilin and Black Basta, and utilizes techniques like memory-based payloads and kill switches. This highlights a trend of initial access brokers developing custom tools for ransomware operations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data