#CoolClient
The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard.
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor
The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard.
www.bleepingcomputer.com
January 27, 2026 at 10:26 PM
HoneyMyte's CoolClient backdoor now uses a kernel rootkit, enhancing stealth and evading detection. #CyberSecurity #HoneyMyte #CoolClient #Rootkit #Malware #ThreatIntel https://thedailytechfeed.com/honeymytes-coolclient-backdoor-employs-kernel-rootkit-for-stealth/
August 17, 2026 at 9:29 AM
📰 Peretas China Mustang Panda Sebarkan Infostealer lewat Backdoor CoolClient

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/01/28/mustang-panda-sebarkan-infostealer-coolclient/

#coo
lc#coolclients#infostealera#keamananr#sibera#malwarea#chinaa#mustanga#panda
January 28, 2026 at 10:03 AM
Notícia da BleepingComputer

"Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor" #bolhasec
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor
The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard.
www.bleepingcomputer.com
February 9, 2026 at 1:30 PM
Mustang Panda Upgrades CoolClient With a Kernel Rootkit

huntaegis.com
August 17, 2026 at 3:17 AM
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor

The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard. [...]
#hackernews #news
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor
The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard. [...]
www.bleepingcomputer.com
January 29, 2026 at 3:55 PM
-Bank hackers arrested in Brazil and EU
-PXA Stealer admin arrested in Vietnam in March
-NC man sentenced for extortion
-ExfilSquad likely hacked Microsoft D365 servers
-Dysphoria botnet reaches 300k
-New Majinahanashi ransomware
-CRPx0 launches leak site
-HoneyMyte updates CoolClient backdoor
August 17, 2026 at 1:19 PM
Mustang PandaがCoolClientをカーネルルートキットでアップグレード

Mustang Pandaとしても知られるHoneyMyteは、CoolClientバックドアをWindowsの奥深くまで浸透させた。カスペル​​スキーの最新の分析によると、署名付きカーネルモードドライバーをWindowsサービスとして展開し、IOCTLリクエストを介して通信し、プロセス、ファイル、レジストリエントリを検査から隠蔽できる新たな亜種が確認された。

その違いは重要です。CoolClientは、キーロギング、クリップボードの窃盗、認証情報の収集、ファイル管理、システム偵察、プラグインアー...
Mustang Panda Upgrades CoolClient With a Kernel Rootkit - Security Affairs
HoneyMyte upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making detection hard.
securityaffairs.com
September 15, 2026 at 12:37 PM
APTグループHoneyMyteがCoolClientをアップグレード:バックドアにカーネルレベルのWindowsルートキットが追加される

CoolClientは、HoneyMyte APTグループ(別名Mustang Panda)が開発したバックドアの一種で、アジアやロシアの組織を標的としたサイバー諜報活動に利用されています。キーロギング、クリップボード情報の窃盗、認証情報の収集、ファイル管理、システム偵察、プラグインによる拡張機能など、様々な機能を備えています。

CoolClientは、 2022年にSophosが初めて公表し、 2023年にTrend Microが分析して以来、...
CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
securelist.com
September 15, 2026 at 1:03 PM
Mustang PandaがCoolClientバックドアに署名付きWindowsルートキットを追加し、ステルス性を高める

HoneyMyte(別名Mustang Panda )として知られる脅威アクターが、悪意のあるプロセス、ファイル、レジストリオブジェクト、およびコマンド&コントロール(C2)ネットワーク情報を隠蔽および保護できる署名付きWindowsカーネルモードルートキットを備えたCoolClientバックドアの更新バージョンを展開していることが確認されています。

ロシアのサイバーセキュリティベンダーであるカスペルスキーは、ミャンマー、モンゴル、パキスタン、ロシアで被害者を確...
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
HoneyMyte deploys an updated CoolClient backdoor with a signed Windows rootkit that hides malicious processes, files, registry objects, and C2 data.
thehackernews.com
September 15, 2026 at 12:52 PM
HoneyMyteがCoolClientをWindowsカーネルルートキットでアップグレードし、マルウェアとC2接続を隠蔽

中国と連携するスパイ集団HoneyMyte(別名Mustang Panda)は、CoolClientバックドアをアップグレードし、マルウェアの痕跡やコマンド&コントロールのインフラストラクチャをセキュリティツールから隠蔽できる署名付きWindowsカーネルモードルートキットを導入した。

この展開は、グループによる侵害後の工作技術が著しくエスカレートしたことを示しており、多くのエンドポイント検査ツールが動作するユーザーモード層よりも下位の層で、保護と回避が行われて...
HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections
HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit.
gbhackers.com
September 15, 2026 at 12:45 PM
Ciberespiões atualizam vírus para invadir órgãos públicos e driblar defesas do Windows
Ciberespiões atualizam vírus para invadir órgãos públicos e driblar defesas do Windows
Nova versão do programa espião CoolClient utiliza componente com assinatura digital para esconder arquivos e roubar dados sem ser detectado por antivírus
www.estadao.com.br
September 10, 2026 at 12:36 PM
CyberIntel headline: China-aligned HoneyMyte Group Upgrades CoolClient with Windows Kernel Rootkit https://cyberintelnews.com/ #Malware #ThreatIntel #Cybersecurity
August 27, 2026 at 6:00 AM
🟢 HoneyMyte Group Updates CoolClient Backdoor and Uses a Windows Kernel-Mode Rootkit

🗨️ Kaspersky Lab researchers have discovered a new version of the CoolClient backdoor, which the HoneyMyte APT group uses…

#news
HoneyMyte Group Updates CoolClient Backdoor and Uses a Windows Kernel-Mode Rootkit
Read more
hackmag.com
August 19, 2026 at 2:30 PM
Novo malware CoolClient utiliza driver do Windows para ocultar espionagem estatal. Uma versão atualizada do programa espião CoolClient está a ser utilizada em ataques coordenados contra entidades governamentais no Paquistão, Mongólia, Mianmar e Rússia.

#driver #espionagem #malware #windows
Novo malware CoolClient usa driver do Windows para ocultar espionagem estatal
Uma versão atualizada do programa espião CoolClient está a ser utilizada em ataques coordenados contra entidades governamentais no Paquistão, Mongólia, Mianmar e Rússia. De acordo com informações avançadas pelo The Hacker News, a nova variante da ameaça é operada pelo grupo cibercriminoso HoneyMyte,
tugatech.com.pt
August 18, 2026 at 1:37 PM
📢 HoneyMyte améliore CoolClient avec un rootkit noyau signé pour masquer processus, fichiers et C2

Cryptika (relayant Cyber Security News / Securelist), publié le 17 août 2026. Les chercheurs de Securelist ont identifié cette…

🟢 vérification factuelle haute
#CoolClient #HoneyMyte #Cyberveille
HoneyMyte améliore CoolClient avec un rootkit noyau signé pour masquer processus, fichiers et C2
Cryptika (relayant Cyber Security News / Securelist), publié le 17 août 2026. Les chercheurs de Securelist ont identifié cette nouvelle variante lors d'investigations menées fin 2025 et en 2026. Le groupe HoneyMyte (acteur de cyberespionnage) a mis à jour son implant CoolClient avec un composant rootkit en mode noyau.
cyberveille.ch
August 18, 2026 at 11:00 AM
HoneyMyte 升级 CoolClient 后门:Windows 内核级根kit 隐藏威胁再升级

https://qian.cx/posts/6DD6F574-491F-415B-BDD8-2BA1F35C1D36
August 18, 2026 at 12:33 PM
Новый уровень угроз: как HoneyMyte превратила CoolClient в руткит с помощью драйвера ядра Windows

https://kripta.biz/posts/8E81572A-B5F3-4070-8DCC-440099BD14F6
August 18, 2026 at 12:32 PM