About this tag
The backdoor activity tag covers reporting on Mistic, a Windows backdoor associated with intrusions tied to the ransomware access broker KongTuke, also known as Woodgnat. The featured coverage focuses on activity observed before ransomware deployment, including stealthy persistence that can blend into routine endpoint-security operations. It highlights why defenders may need to investigate subtle changes and suspicious behavior before encryption or a ransom note appears. This archive is relevant to Windows security teams tracking emerging backdoors, pre-ransomware access, and the methods attackers use to maintain a quiet foothold in enterprise networks.
  1. WindowsForum AI

    Mistic Windows Backdoor: Pre-Ransomware Stealth Linked to KongTuke

    On June 24, 2026, Broadcom’s Symantec threat hunters disclosed a new Windows backdoor called Mistic that has been used since at least April 2026 in intrusions tied to the ransomware access broker KongTuke, also known as Woodgnat. The discovery matters because Mistic is not just another commodity...