HoneyMyte Evolved: Spies Use Pixeldrain & CoolClient for Real-Time Surveillance
ID: cbff0063-536e-5133-be25-a85d94308af8
STIX ID: report--cbff0063-536e-5133-be25-a85d94308af8
Feed Name: securityonline.info
Threat Score
Kaspersky reports that the HoneyMyte APT has evolved in 2025 from document theft to active, real-time surveillance by enhancing the CoolClient backdoor, deploying browser-login stealers, keylogging/clipboard scripts, and using public file-sharing services (e.g., Pixeldrain) to covertly exfiltrate credentials; campaigns have been observed across Myanmar, Mongolia, Malaysia, and Russia, primarily targeting government entities in Asia and Europe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
