Signal

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-24 10:41 UTCUpdated 2026-06-24 12:00 UTC
rss
linked_muddywater_poses
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The post New ‘Mistic’ RAT Opens Door to Several Ransomware Families appeared first on SecurityWeek .

Score total
1.24
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
All evidence
All evidence
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage
Infosecurity Magazine · infosecurity-magazine.com · 2026-06-24 12:00 UTC
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
SecurityWeek · securityweek.com · 2026-06-24 11:42 UTC
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
bleepingcomputer_all · bleepingcomputer.com · 2026-06-24 10:41 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • Infosecurity Magazine (1)
  • SecurityWeek (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • infosecurity-magazine.com (1)
  • securityweek.com (1)
  • bleepingcomputer.com (1)