HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic
Brief
HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders.
It gives intruders tools designed to survive ordinary security checks. The activity targeted organizations in Pakistan, Mongolia, Myanmar and Russia, including government entities.
In Myanmar, attackers first used PlugX, then installed CoolClient as a second backdoor.
The sequence resembles PlugX USB worm activity reported in other campaigns, where a trusted program is abused to start malicious code. It also shows the group is layering tools rather than relying on one implant.
Researchers from Securelist identified the new variant during late 2025 and 2026 investigations.
