Backdoor.Mistic: Woodgnat Access Broker Sells Network Entry to Ransomware Gangs
Backdoor.Mistic (Zscaler: MLTBackdoor), used since April 2026 by the access broker Woodgnat/KongTuke, is a fileless RAT that establishes durable remote access and sells it to ransomware crews including Qilin, Akira, and Black Basta. It spreads via fake IT-helpdesk lures on Microsoft Teams.