Kaspersky Links HoneyMyte to New CoolClient Cyber-Espionage Campaign

Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also known as Mustang Panda, in a 2026
Kaspersky Links HoneyMyte to New CoolClient Cyber-Espionage Campaign
Published on
2 min read

Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also known as Mustang Panda, in a 2026 cyber-espionage campaign across Asia and Russia. The malware uses a signed kernel driver, software that runs deep in the system to hide on infected Windows devices. In the observed campaign the actor used PlugX, another backdoor commonly deployed after an initial breach, to deliver the CoolClient components.

The latest CoolClient variant is designed to operate with a stealthy profile and make remediation more difficult. It deploys a signed driver that runs deep within Windows to help hide the malware’s presence, protect related files and registry entries from inspection or modification and support the backdoor’s activity on the infected system.

Before deploying the malware, the attacker configured Microsoft Defender to ignore a specific folder and file. These exclusions covered a fake Windows Defender directory and a renamed executable, defender.exe. The attacker then created the fake directory, copied the CoolClient files into it, and renamed a legitimate Sangfor program to defender.exe so it could be used to load malicious code.

To maintain access after a reboot, the attacker created a scheduled task that launched defender.exe automatically at startup with the highest local Windows privileges. When executed, it loaded a malicious libngs.dll file triggering the CoolClient infection chain.

“The latest CoolClient variant represents a significant evolution of the malware. Rather than operating solely as a user-mode backdoor with plugin support, it now deploys and communicates with a kernel-mode driver that extends its capabilities beyond earlier versions. Through this driver, CoolClient can hide and protect processes, files and registry objects, as well as filter selected network information, making detection and analysis considerably more difficult. For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT.

𝐒𝐭𝐚𝐲 𝐢𝐧𝐟𝐨𝐫𝐦𝐞𝐝 𝐰𝐢𝐭𝐡 𝐨𝐮𝐫 𝐥𝐚𝐭𝐞𝐬𝐭 𝐮𝐩𝐝𝐚𝐭𝐞𝐬 𝐛𝐲 𝐣𝐨𝐢𝐧𝐢𝐧𝐠 𝐭𝐡𝐞 WhatsApp Channel now! 👈📲

𝑭𝒐𝒍𝒍𝒐𝒘 𝑶𝒖𝒓 𝑺𝒐𝒄𝒊𝒂𝒍 𝑴𝒆𝒅𝒊𝒂 𝑷𝒂𝒈𝒆𝐬 👉 FacebookLinkedInTwitterInstagram

logo
DIGITAL TERMINAL
digitalterminal.in