Skip to content
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth

HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth

First seen 14 Aug 2026, 16:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 15, 2026 at 16:22 UTC

The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a signed kernel-mode driver that enhances the malware's stealth, allowing it to hide processes and protect files from detection. The attack method involves using the PlugX backdoor for initial access, followed by the deployment of CoolClient components. The attackers configured Microsoft Defender to ignore a fake Windows Defender directory and renamed a legitimate executable to facilitate the malware's execution. The updated CoolClient can now communicate with the kernel driver through IOCTL requests, significantly complicating remediation efforts. This evolution marks a significant increase in the malware's capabilities and poses a serious threat to targeted organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2025-01-01
Previous CoolClient variant introduced clipboard theft
A variant of CoolClient released in 2025 added clipboard theft and HTTP traffic interception capabilities.
Securelist
2026-08-14
HoneyMyte APT deploys upgraded CoolClient backdoor
The new CoolClient variant includes a signed kernel driver, enhancing stealth and complicating detection.
Kaspersky
2026-08-14
Securelist reports on CoolClient's kernel-mode driver
The latest CoolClient variant can hide processes and protect files, complicating remediation efforts.
Securelist

More articles in this cluster (10)

Following this threat?

Track Earth Preta, LuminousMoth and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed