HoneyMyte CoolClient Rootkit Hooks Windows Nsiproxy to Conceal C2 Addresses
Brief
The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode rootkit that hides command-and-control (C2) infrastructure on compromised Windows systems.
The new capability marks a major shift for the malware, which was previously known mainly as a user-mode espionage tool. CoolClient has been linked to HoneyMyte campaigns targeting organizations across Asia and Russia.
The backdoor supports keylogging, clipboard theft, credential harvesting, file operations, system reconnaissance, and plugin-based expansion. Recent attacks were observed in Myanmar, Mongolia, Pakistan, and Russia, including against government entities.
Researchers found that HoneyMyte often uses PlugX as the initial implant after a breach. PlugX then helps deploy CoolClient and its supporting files.
