HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns
ID: ac5d01db-6909-58e0-9d48-769c9c9c4807
STIX ID: report--ac5d01db-6909-58e0-9d48-769c9c9c4807
Feed Name: Securelist by Kaspersky
Threat Score
This report details Kaspersky's analysis of HoneyMyte APT operations across Asia and Europe, describing an updated CoolClient backdoor (DLL sideloading, multi-stage loaders, plugins, keylogging, clipboard and HTTP proxy credential stealing), browser credential stealers for Chromium/Edge/Firefox, PowerShell and batch data‑theft scripts, campaign infrastructure and IOCs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
