CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4517

As cited

Copy frozen at (site build).

threat intel

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

HoneyMyte (also called Mustang Panda) has deployed an updated version of the CoolClient backdoor that incorporates a signed Windows kernel-mode rootkit, allowing the malware to hide malicious processes, files, registry objects, and command-and-control (C2) communications. Kaspersky identified victims in Myanmar, Mongolia, and Pakistan.

Why it matters: Organizations in Southeast Asia, Central Asia, and South Asia should assess exposure to HoneyMyte campaigns and review endpoint detection for unsigned kernel drivers or anomalous process hiding behavior indicative of rootkit deployment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

HoneyMyte (also called Mustang Panda) has deployed an updated version of the CoolClient backdoor that incorporates a signed Windows kernel-mode rootkit, allowing the malware to hide malicious processes, files, registry objects, and command-and-control (C2) communications. Kaspersky identified victims in Myanmar, Mongolia, and Pakistan.

Why it matters: Organizations in Southeast Asia, Central Asia, and South Asia should assess exposure to HoneyMyte campaigns and review endpoint detection for unsigned kernel drivers or anomalous process hiding behavior indicative of rootkit deployment.

VendorsMicrosoft
Actorsmustang panda
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary