logo

Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor

ID: dda518e0-333b-5dbc-b4ce-ae72990649e4

STIX ID: report--dda518e0-333b-5dbc-b4ce-ae72990649e4

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky reports that Mustang Panda has evolved its CoolClient backdoor into a more capable variant that now includes clipboard monitoring, active window tracking, HTTP proxy credential sniffing, and dedicated browser infostealer plugins; operators have used it (and a newly observed rootkit) against government targets across Myanmar, Mongolia, Malaysia, Russia, and Pakistan, deploying via legitimate Sangfor software and previously abused signed binaries to achieve persistence, privilege escalation, and versatile remote-control operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.