← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Mustang Panda's CoolClient Backdoor Now Uses Signed Windows Kernel-Mode Rootkit

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Mustang Panda updated CoolClient with a signed Windows kernel-mode rootkit.
  • The rootkit hides malicious processes, files, registry, and C2 information.
  • Victims include government entities in Myanmar, Mongolia, Pakistan, and Russia.
  • CoolClient is often deployed after a PlugX infection.

CoolClient Backdoor Enhanced with Kernel Rootkit

The threat actor known as Mustang Panda, also identified as HoneyMyte, has been observed deploying an updated version of its CoolClient backdoor. This new variant incorporates a signed Windows kernel-mode rootkit. The rootkit's primary function is to hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information from detection.

Targeted Victims and Deployment Conditions

Russian cybersecurity vendor Kaspersky identified victims in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities. CoolClient is consistently deployed as a secondary backdoor following an initial PlugX infection. The kernel component is deployed only when CoolClient has full access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege; otherwise, the malware proceeds without driver deployment.

Increased Stealth Capabilities

Kaspersky's analysis confirms this is a new CoolClient variant associated with the HoneyMyte group. While the overall execution flow remains consistent with previous versions, the introduction of the kernel-mode driver significantly expands the malware’s stealth capabilities. The latest CoolClient variant can install the driver as a Windows service and control it from the user-mode backdoor using input/output control (IOCTL) requests.

CoolClient Functionality and Initial Infection Vector

CoolClient supports various malicious activities, including keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and additional functionality through plugins. In one campaign targeting Myanmar, HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient. This involved adding Microsoft Defender exclusions, renaming a legitimate Sangfor executable for DLL sideloading, and establishing persistence via a scheduled task with SYSTEM privileges.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 13 stories · Aug 17

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The threat actor Mustang Panda (HoneyMyte) has updated its CoolClient backdoor to include a signed Windows kernel-mode rootkit, enhancing its ability to hide malicious activity. This new component allows the malware to conceal processes, files, registry objects, and C2 network information, making detection and removal more difficult for cybersecurity defenses.