threat-intel
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
High
Summary
A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026. The backdoor, alongside ModeloRAT, utilizes ClickFix campaigns and DLL side-loading techniques to gain persistent access, raising concerns about opportunistic targeting and potential ransomware operations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
