Back to Blog
KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access Broker Operations (June 2024)
ransomware

KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access Broker Operations (June 2024)

breachwire TeamJun 29, 20265 min read

KongTuke: What Happened

In June 2024, threat intelligence confirmed that the Mistic backdoor was deployed in financially motivated attacks attributed to the access broker KongTuke. Multiple organizations across the insurance, education, IT, and professional services sectors were targeted. KongTuke, active since 2024, specializes in compromising corporate networks and selling persistent access to ransomware groups. The Mistic backdoor facilitated long-term, stealthy footholds, allowing follow-on ransomware operations by various threat actors.

Attack Vector & Technical Detail

The attack chain began with the deployment of the Mistic backdoor, leveraging side-loading techniques such as MpExtMs.exe loading a malicious version.dll. The loader component, EndpointDlp.dll, was observed in several incidents, alongside the use of a fake login screen .NET DLL to harvest credentials. Additional payloads included ModeloRAT and MTLBackdoor, with the ClickFix infection chain and Beacon Object Files (BOFs) used for in-memory code execution. MITRE tactics associated with this campaign include Initial Access (TA0001), Defense Evasion (TA0005), Discovery (TA0007), Collection (TA0009), and Command and Control (TA0011). No CVEs were specifically linked in these incidents, indicating a reliance on living-off-the-land and side-loading techniques rather than public vulnerabilities.

Confirmed Impact

The confirmed impact includes persistent, undetected access to victim networks, enabling attackers to upload, download, modify, and delete files, as well as execute arbitrary code. The global reach of the campaign affected organizations in multiple sectors, increasing the risk of data exfiltration, operational disruption, and subsequent ransomware deployment. The stealthy nature of Mistic complicates detection and response, raising concerns for compliance with data protection regulations and incident reporting requirements in affected jurisdictions.

What This Means for Your Organization

Organizations in targeted sectors should be aware that access brokers like KongTuke are facilitating ransomware operations by maintaining covert access for extended periods. The use of side-loading and in-memory execution techniques makes traditional endpoint detection less effective. Defenders must prioritize behavioral monitoring, application whitelisting, and regular review of credential usage. Proactive threat hunting for IOCs such as MpExtMs.exe, EndpointDlp.dll, and anomalous .NET DLL activity is critical to disrupt these attack chains before ransomware deployment.

Detection & Response

  • Immediate: Isolate systems where MpExtMs.exe or EndpointDlp.dll are detected and initiate a full forensic review.
  • Hunt: Search for the presence of MpExtMs.exe side-loading version.dll, EndpointDlp.dll, fake login screen .NET DLLs, and evidence of Beacon Object Files (BOFs) in memory.
  • Patch: N/A (no specific CVEs identified in this campaign).

Source: https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: