Dossier
Carbon Black's Threat Hunter Team
Coverage of Carbon Black's Threat Hunter Team in the Nexus archive.
- New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
A new backdoor named Mistic (MLTBackdoor) has been used in financially motivated attacks targeting organizations in insurance, education, IT, and professional services since April 2026. Symantec and Carbon Black's Threat Hunter Team linked it to an initial access broker named KongTuke and campaigns called ClickFix and ModeloRAT.
- Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Hackers accessed a senior executive's Outlook mailbox at a major global stock exchange for five months, using Dropbox and OneDrive to exfiltrate inbox data in small batches. Symantec and Carbon Black's Threat Hunter Team identified the campaign as espionage-related, not financially motivated.