securityonline.info 8/19/2026, 10:22:54 AM · external

HoneyMyte updates CoolClient rootkit to spy on Asian, Russian govt

HoneyMyte updates CoolClient rootkit to spy on Asian, Russian govt
Developing story campaign 3 articles tracked
HoneyMyte (Mustang Panda) updates CoolClient backdoor with signed kernel driver
CyberSIXT Evidence Panel
Primary Source securelist.com
Threat Actor
🇨🇳 MUSTANG PANDA

THE content discusses recent cybersecurity threats, specifically focusing on an updated variant of the HoneyMyte CoolClient rootkit, which targets government entities and organizations in Asia and Russia. Key points include:

1. **Threat Details:** The HoneyMyte group, known for cyber-espionage, has refined the CoolClient rootkit to include a signed kernel-mode driver that enables stealthy installation and operation within infected systems.

2. **Attack Mechanism:** Attackers deploy this rootkit following an initial infection, using legitimate binaries to sideload malicious components, allowing them to avoid detection by standard security measures like Windows Defender.

3. **Malware Functionality:** The rootkit actively hides processes and network traffic from detection tools, complicating analysis and mitigation efforts. It also modifies Windows kernel structures directly to mask its presence.

4. **Victims and Scale:** Notable targets include government agencies in Myanmar, Mongolia, Pakistan, and Russia, with the malware capable of stealing sensitive information and facilitating prolonged surveillance.

5. **Defensive Measures:** Security teams are advised to monitor for changes in Windows Defender settings, inspect installed drivers, and block known malicious infrastructure to mitigate the risk of infection.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline