Skip to content
Mustang Panda Escalates Cyber-Espionage with Updated CoolClient Backdoor

Mustang Panda Escalates Cyber-Espionage with Updated CoolClient Backdoor

First seen 28 Jan 2026, 14:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Mustang Panda group has intensified its cyber-espionage efforts by deploying a new variant of the CoolClient backdoor, which includes advanced infostealer capabilities. This updated malware targets government and critical infrastructure organizations primarily in Asia and Eastern Europe, with the ability to steal browser login data and monitor clipboard activity. The malware has been associated with Mustang Panda since 2022 and has also been linked to a previously unseen rootkit.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track Bronze President and PlugX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed