Mustang Panda Upgrades CoolClient With a Kernel Rootkit
ID: d47b9ff8-b270-5849-b7eb-8062a8d500ea
STIX ID: report--d47b9ff8-b270-5849-b7eb-8062a8d500ea
Feed Name: Security Affairs
Mustang Panda (HoneyMyte) upgraded the CoolClient espionage backdoor by adding a signed kernel-mode driver (msagent.sys) that communicates via IOCTL to hide processes, files, and registry entries and to filter network information, significantly increasing the malware's stealth; Kaspersky observed this variant in campaigns across Pakistan, Mongolia, Myanmar and Russia and describes infection via PlugX, DLL sideloading (fake Windows Defender folder and defender.exe), scheduled tasks/services for persistence, and numerous powerful but not always used kernel capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
