New Stealthy Backdoor 'Mistic' Deployed in Financially Motivated Attacks
Patch any exposed systems that might have been compromised by the Mistic backdoor.
Patch any exposed systems that might have been compromised by the Mistic backdoor.
Summary
A stealthy backdoor dubbed Mistic, also known as MLTBackdoor, has been identified in a series of financially motivated attacks that began in April 2026.
The threat actor has targeted a diverse set of sectors, including insurance, education, IT, and professional services, indicating a broad campaign.
Symantec and Carbon Black's Threat Hunter Team linked the backdoor to an initial access broker (IAB) that appears to be orchestrating the compromise chain.
Mistic is designed to provide persistent access and exfiltration capabilities, though the full extent of its payload remains under investigation.
Early indicators suggest the backdoor may be leveraging stolen credentials and exploiting known vulnerabilities in legacy systems.
Security teams are advised to conduct thorough scans for the Mistic signature and review any anomalous outbound traffic.
Key changes
- Backdoor named Mistic (also MLTBackdoor)
- Deployed since April 2026
- Targets insurance, education, IT, professional services
- Linked to an initial access broker (IAB)
- Suspected financially motivated attacks