The threat actor known as Mustang Panda, also identified as HoneyMyte, has been observed deploying an updated version of its CoolClient backdoor. This new variant incorporates a signed Windows kernel-mode rootkit. The rootkit's primary function is to hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information from detection.
Russian cybersecurity vendor Kaspersky identified victims in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities. CoolClient is consistently deployed as a secondary backdoor following an initial PlugX infection. The kernel component is deployed only when CoolClient has full access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege; otherwise, the malware proceeds without driver deployment.
Kaspersky's analysis confirms this is a new CoolClient variant associated with the HoneyMyte group. While the overall execution flow remains consistent with previous versions, the introduction of the kernel-mode driver significantly expands the malware’s stealth capabilities. The latest CoolClient variant can install the driver as a Windows service and control it from the user-mode backdoor using input/output control (IOCTL) requests.
CoolClient supports various malicious activities, including keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and additional functionality through plugins. In one campaign targeting Myanmar, HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient. This involved adding Microsoft Defender exclusions, renaming a legitimate Sangfor executable for DLL sideloading, and establishing persistence via a scheduled task with SYSTEM privileges.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The threat actor Mustang Panda (HoneyMyte) has updated its CoolClient backdoor to include a signed Windows kernel-mode rootkit, enhancing its ability to hide malicious activity. This new component allows the malware to conceal processes, files, registry objects, and C2 network information, making detection and removal more difficult for cybersecurity defenses.