Securelist
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a signed kernel-mode driver that enhances the malware's stealth, allowing it to hide processes and protect files from detection. The attack method involves using the PlugX backdoor for initial access, followed by the deployment of CoolClient components. The attackers configured Microsoft Defender to ignore a fake Windows Defender directory and renamed a legitimate executable to facilitate the malware's execution. The updated CoolClient can now communicate with the kernel driver through IOCTL requests, significantly complicating remediation efforts. This evolution marks a significant increase in the malware's capabilities and poses a serious threat to targeted organizations.
Key Points: • HoneyMyte APT's CoolClient backdoor now includes a kernel-mode driver for enhanced stealth. • The malware targets organizations in Myanmar, Mongolia, Pakistan, India, and Russia. • Attackers use PlugX for initial access, followed by deploying CoolClient components.