All incidents

Mustang Panda updates CoolClient backdoor with signed kernel driver

malwareopenAug 14, 2026 — Aug 16, 2026
Mustang Panda updates CoolClient backdoor with signed kernel driver

MUSTANG Panda has updated its CoolClient backdoor with a signed kernel driver, according to analysis by researchers. The upgraded malware has been spotted in intrusion campaigns across Pakistan, Mongolia and Myanmar, where it hides its presence more effectively than previous versions.

The new component is a kernel‑mode driver that carries a valid digital signature, which lets the malware conceal its processes, files and registry entries from security tools. It works by hooking core system functions, allowing the backdoor to hide its own activity while retaining capabilities such as keylogging and clipboard theft.

Persistence is achieved through scheduled tricks that launch a legitimate‑looking executable which then side‑loads a malicious DLL, a technique often used to bypass application controls. The driver also interferes with User Account Control prompts, making it harder for administrators to spot the infection.

Researchers link the activity to the HoneyMyte APT group, noting that the backdoor has been used in espionage campaigns across Pakistan, Mongolia and Myanmar as well as targets in Russia. The addition of a signed driver complicates attribution because the certificate appears to belong to a trusted third‑party vendor.

Defenders should scan for kernel drivers that are signed but not recognised by the organisation, monitor for the creation of unusual scheduled tasks and inspect any DLLs loaded via known sideloading paths. Verifying the publisher of each driver and blocking any that originate from unknown sources can reduce the risk of stealthy infection.

Endpoint detection platforms need to be tuned to alert on attempts to load unsigned or poorly signed drivers, while credential access logs should be reviewed for abnormal patterns. Keeping threat intelligence feeds up to date with the latest indicators from the CoolClient campaign will help security teams respond quickly.

Intelligence briefing updated Aug 17, 2026

MUSTANG PANDA
Root sourcesecurelist.com
Timeline Coverage

Swipe to explore timeline