THE article discusses the CoolClient backdoor attributed to the HoneyMyte APT group, which has evolved to include a kernel-mode driver enhancing its stealth and operational capabilities. Initially documented in 2022, the malware has been used in cyber-espionage campaigns targeting organizations in Asia and Russia, employing techniques like keylogging and credential harvesting.
The latest variant introduces significant enhancements, including hiding the malware's processes and installation paths from security tools, and bypassing user account controls. This article analyzes the technical aspects of the CoolClient malware, including its execution stages and the use of DLL sideloading, process injection, and auto-run persistence mechanisms. The findings confirm the malware's association with HoneyMyte's activities and note its deployment following a PlugX infection.
Key points include its communication with a kernel-mode driver, making detection challenging, and highlighting the threat's persistence in ongoing cyber-espionage efforts.