APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
ID: 89b7e7fa-f519-55be-a64f-ba74873e6716
STIX ID: report--89b7e7fa-f519-55be-a64f-ba74873e6716
Feed Name: Securelist by Kaspersky
**Executive summary:** This report analyzes a new CoolClient backdoor variant attributed to the HoneyMyte (Mustang Panda) APT that augments its user-mode implant with a signed kernel-mode driver (msagent.sys) to hide and protect processes, files, and registry objects, filter network data (C2 addresses), and resist inspection; the document covers the multi-stage loader, persistence (scheduled task, Run key, service), UAC bypass, driver IOCTLs and callbacks, observed victimology in Asia and Russia, and provides IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
