logo

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

ID: 89b7e7fa-f519-55be-a64f-ba74873e6716

STIX ID: report--89b7e7fa-f519-55be-a64f-ba74873e6716

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2026-08-14

Date Updated: 2026-08-14

Author: Fareed Radzi

...
...

**Executive summary:** This report analyzes a new CoolClient backdoor variant attributed to the HoneyMyte (Mustang Panda) APT that augments its user-mode implant with a signed kernel-mode driver (msagent.sys) to hide and protect processes, files, and registry objects, filter network data (C2 addresses), and resist inspection; the document covers the multi-stage loader, persistence (scheduled task, Run key, service), UAC bypass, driver IOCTLs and callbacks, observed victimology in Asia and Russia, and provides IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.