Rescana
Mustang Panda Escalates Cyber-Espionage with Updated CoolClient Backdoor
First seen 28 Jan 2026, 14:06 UTC
•

•83% similarity
•57.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Mustang Panda group has intensified its cyber-espionage efforts by deploying a new variant of the CoolClient backdoor, which includes advanced infostealer capabilities. This updated malware targets government and critical infrastructure organizations primarily in Asia and Eastern Europe, with the ability to steal browser login data and monitor clipboard activity. The malware has been associated with Mustang Panda since 2022 and has also been linked to a previously unseen rootkit.
ThreatCluster AI
How this analysis works