← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 17, 2026 · 05:57via CyberPress

HoneyMyte CoolClient Rootkit Hooks Windows Nsiproxy to Conceal C2 Addresses

Brief

The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode rootkit that hides command-and-control (C2) infrastructure on compromised Windows systems.

The new capability marks a major shift for the malware, which was previously known mainly as a user-mode espionage tool. CoolClient has been linked to HoneyMyte campaigns targeting organizations across Asia and Russia.

The backdoor supports keylogging, clipboard theft, credential harvesting, file operations, system reconnaissance, and plugin-based expansion. Recent attacks were observed in Myanmar, Mongolia, Pakistan, and Russia, including against government entities.

Researchers found that HoneyMyte often uses PlugX as the initial implant after a breach. PlugX then helps deploy CoolClient and its supporting files.

Read more on CyberPress