HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth

HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth

First seen 14 Aug 2026, 16:28 UTC SecurelistKasperskywww.sophos.comwww.trendmicro.comprojectzero.google 88% similarity 75.5

Article Content

Browse articles
ThreatCluster

The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a signed kernel-mode driver that enhances the malware's stealth, allowing it to hide processes and protect files from detection. The attack method involves using the PlugX backdoor for initial access, followed by the deployment of CoolClient components. The attackers configured Microsoft Defender to ignore a fake Windows Defender directory and renamed a legitimate executable to facilitate the malware's execution. The updated CoolClient can now communicate with the kernel driver through IOCTL requests, significantly complicating remediation efforts. This evolution marks a significant increase in the malware's capabilities and poses a serious threat to targeted organizations.

Key Points: • HoneyMyte APT's CoolClient backdoor now includes a kernel-mode driver for enhanced stealth. • The malware targets organizations in Myanmar, Mongolia, Pakistan, India, and Russia. • Attackers use PlugX for initial access, followed by deploying CoolClient components.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
Previous CoolClient variant introduced clipboard theft
A variant of CoolClient released in 2025 added clipboard theft and HTTP traffic interception capabilities.
Securelist
2026-08-14
HoneyMyte APT deploys upgraded CoolClient backdoor
The new CoolClient variant includes a signed kernel driver, enhancing stealth and complicating detection.
Kaspersky
2026-08-14
Securelist reports on CoolClient's kernel-mode driver
The latest CoolClient variant can hide processes and protect files, complicating remediation efforts.
Securelist

Community

Browse all →