Mustang Panda Escalates Cyber-Espionage with Updated CoolClient Backdoor

Mustang Panda Escalates Cyber-Espionage with Updated CoolClient Backdoor

First seen 28 Jan 2026, 14:06 UTC BleepingcomputerRescanaWebpronews 83% similarity 57.9

Article Content

Browse articles
ThreatCluster

The Mustang Panda group has intensified its cyber-espionage efforts by deploying a new variant of the CoolClient backdoor, which includes advanced infostealer capabilities. This updated malware targets government and critical infrastructure organizations primarily in Asia and Eastern Europe, with the ability to steal browser login data and monitor clipboard activity. The malware has been associated with Mustang Panda since 2022 and has also been linked to a previously unseen rootkit.

ThreatCluster AI How this analysis works

Community

Browse all →