IT2 мин. чтения

Mistic Backdoor Linked to KongTuke Group in ClickFix and ModeloRAT Attacks

Security researchers discovered the new Mistic backdoor in April 2026, actively used by KongTuke group in attacks targeting insurance, education, IT and professional services sectors.

Mistic Backdoor Linked to KongTuke Group in ClickFix and ModeloRAT Attacks
Cybersecurity illustration showing a padlock and hacker silhouette

April 2026 - Cybersecurity researchers uncovered the new Mistic backdoor being actively deployed by the KongTuke threat group. The attacks have hit organizations in insurance, education, IT services, and professional sectors. This remote access trojan gives attackers full control over compromised systems, creating significant data privacy and financial security risks.

Mistic backdoor attack chain diagram

What we know about Mistic backdoor

First identified in April 2026 (also tracked as MLTBackdoor), this stealthy malware provides attackers with persistent remote access to compromised devices. Key characteristics:

  • Evasion: Bypasses standard security controls
  • Remote control: Full command execution capability
  • Financial motivation: Used for data theft and extortion schemes

Attackers behind the campaign

KongTuke group - previously tied to ClickFix and ModeloRAT attacks - operates as an Initial Access Broker (IAB) according to Symantec and Carbon Black. The group sells network access to ransomware operators and other threat actors. Primary targets:

  • Organizations with vulnerable internet-facing systems
  • Companies storing sensitive customer/business data
  • High-value financial sector entities

Mistic infection chain

The backdoor employs multiple techniques for initial access and persistence:

  • Phishing emails: Primary delivery method
  • Exploit kits: Leverages known vulnerabilities
  • Process hollowing: Masquerades as legitimate system processes

Why this matters now

With attack frequency increasing across critical sectors, Mistic represents evolved tradecraft requiring immediate defensive action. Primary risks:

  • Sensitive data exfiltration
  • Financial losses from extortion or theft
  • Long-term undetected network presence

Recommended actions

To mitigate Mistic-related threats:

  • Patch all systems and update endpoint protection
  • Conduct threat hunting for suspicious process activity
  • Implement phishing awareness training

Questions & answers

Which organizations are most at risk?

Insurance providers, educational institutions, IT services firms, and professional organizations with weaker security postures face highest exposure.

How to detect Mistic infection?

Watch for unusual network connections, system slowdowns, and suspicious processes in Task Manager.

What are the most effective defenses?

Timely patching, next-gen AV solutions with behavioral detection, and employee security training.

Is Mistic related to other known malware?

Yes, KongTuke group also operates the ClickFix and ModeloRAT backdoors in similar campaigns.