Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor
ID: dda518e0-333b-5dbc-b4ce-ae72990649e4
STIX ID: report--dda518e0-333b-5dbc-b4ce-ae72990649e4
Feed Name: Bleeping Computer
Kaspersky reports that Mustang Panda has evolved its CoolClient backdoor into a more capable variant that now includes clipboard monitoring, active window tracking, HTTP proxy credential sniffing, and dedicated browser infostealer plugins; operators have used it (and a newly observed rootkit) against government targets across Myanmar, Mongolia, Malaysia, Russia, and Pakistan, deploying via legitimate Sangfor software and previously abused signed binaries to achieve persistence, privilege escalation, and versatile remote-control operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
