logo

HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

ID: ac5d01db-6909-58e0-9d48-769c9c9c4807

STIX ID: report--ac5d01db-6909-58e0-9d48-769c9c9c4807

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2026-01-27

Date Updated: 2026-04-29

Author: Fareed Radzi

...
...

This report details Kaspersky's analysis of HoneyMyte APT operations across Asia and Europe, describing an updated CoolClient backdoor (DLL sideloading, multi-stage loaders, plugins, keylogging, clipboard and HTTP proxy credential stealing), browser credential stealers for Chromium/Edge/Firefox, PowerShell and batch data‑theft scripts, campaign infrastructure and IOCs to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.