Skip to content
← All Threat Actors
Cybercrime high Unknown (Eastern Europe assessed)

KongTuke

Cybercrime — initial access broker (IAB) · Financial — selling verified corporate network access to ransomware operators

Reports 1
Active Since 2026
Last Reported 26 Jun 2026
Sectors Targeted finance, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Mistic/Woodgnat fileless backdoor: executes entirely in memory with no disk artifacts, defeating signature-based endpoint detection
  • ClickFix and FileFix social engineering lures: fake CAPTCHA pages or browser update prompts delivering PowerShell via Windows Run dialog
  • Self-destruct kill switch in Mistic — backdoor erases from memory on detection or operator command, complicating forensic investigation
  • ModeloRAT secondary access tool deployed alongside Mistic for redundant persistence
  • Pure access broker model: KongTuke does not directly conduct ransomware operations, limiting personal legal exposure
  • Verified access sales to at least six ransomware groups: Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta

Known Targets

Insurance sector organisationsEducational institutionsIT service providers (high-value supply chain access)Professional services firmsFinance sector organisations

Analyst Notes

KongTuke emerged April 2026 as a pure initial access broker. Its defining technical feature is the Mistic/Woodgnat fileless backdoor — memory-resident with a kill switch that erases the implant on detection, frustrating endpoint forensics. KongTuke acquires footholds via ClickFix/FileFix social engineering and sells verified access to ransomware operators, avoiding the operational and legal exposure of running ransomware directly. With confirmed sales to six ransomware groups in its first months, KongTuke represents efficient access commoditisation in the ransomware supply chain. Attacks attributed to Qilin, Rhysida, Akira, and Black Basta may trace initial access to KongTuke.

Also Known As

Mistic (backdoor designation)Woodgnat (alternate backdoor name)