Symantec ties new Mistic backdoor to ransomware broker KongTuke
Symantec links a stealth in-memory backdoor used since April 2026 to KongTuke (Woodgnat), the initial-access broker that has fed Interlock, Rhysida, Akira, 8Base and Black Basta.
Symantec links a stealth in-memory backdoor used since April 2026 to KongTuke (Woodgnat), the initial-access broker that has fed Interlock, Rhysida, Akira, 8Base and Black Basta.