Securelist HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
Article Content
- •HoneyMyte APT's CoolClient backdoor now includes a kernel-mode driver for enhanced stealth.
- •The malware targets organizations in Myanmar, Mongolia, Pakistan, India, and Russia.
- •Attackers use PlugX for initial access, followed by deploying CoolClient components.
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a signed kernel-mode driver that enhances the malware's stealth, allowing it to hide processes and protect files from detection. The attack method involves using the PlugX backdoor for initial access, followed by the deployment of CoolClient components. The attackers configured Microsoft Defender to ignore a fake Windows Defender directory and renamed a legitimate executable to facilitate the malware's execution. The updated CoolClient can now communicate with the kernel driver through IOCTL requests, significantly complicating remediation efforts. This evolution marks a significant increase in the malware's capabilities and poses a serious threat to targeted organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Earth Preta, LuminousMoth and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mustang Panda Escalates Cyberattacks on European Maritime Sector Chinese hacking group Mustang Panda has intensified cyberespionage campaigns targeting maritime organizations across at least seven EU member states throughout 2025. The European Union Agency for Cybersecurity (ENISA) reported that these attacks primarily focus on espionage and strategic intelligence collection, with…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…