news.mlab.sh
Back to the feed
threat-intel

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

High
Image: The Hacker News
Summary

A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026. The backdoor, alongside ModeloRAT, utilizes ClickFix campaigns and DLL side-loading techniques to gain persistent access, raising concerns about opportunistic targeting and potential ransomware operations.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.