Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Aug 14, 2026
Malware / Threat Intelligence
The threat actor known as HoneyMyte (aka Mustang Panda ) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, with CoolClient consistently deployed as a secondary backdoor following a PlugX infection. The kernel component is deployed when CoolClient has full access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege. If those conditions are not met, the malware skips driver deployment and proceeds to the final-stage implant. Kaspersky has also published file hashes, paths, and C2 domains as indicators of compromise (IoCs). "Our analysis confirms that the investigated malware is a new CoolClient variant ...