logo

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

ID: d47b9ff8-b270-5849-b7eb-8062a8d500ea

STIX ID: report--d47b9ff8-b270-5849-b7eb-8062a8d500ea

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-08-16

Date Updated: 2026-08-16

Author: Pierluigi Paganini

...
...

Mustang Panda (HoneyMyte) upgraded the CoolClient espionage backdoor by adding a signed kernel-mode driver (msagent.sys) that communicates via IOCTL to hide processes, files, and registry entries and to filter network information, significantly increasing the malware's stealth; Kaspersky observed this variant in campaigns across Pakistan, Mongolia, Myanmar and Russia and describes infection via PlugX, DLL sideloading (fake Windows Defender folder and defender.exe), scheduled tasks/services for persistence, and numerous powerful but not always used kernel capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.