HoneyMyte’s CoolClient Malware Now Hides Behind a Windows Rootkit


rootkit windows 11
Image credit: Microsoft

HoneyMyte has upgraded its CoolClient backdoor with a Windows rootkit that gives the malware stronger protection against detection, removal, and security tools.

Kaspersky says the HoneyMyte APT group, also known as Mustang Panda, added a kernel-level component to the latest CoolClient version.

Researchers observed the updated malware in attacks targeting systems in several Asian countries, including Pakistan, Mongolia, and Myanmar.

CoolClient now runs deeper inside Windows

The new CoolClient variant installs a signed kernel-mode driver as a Windows service. The driver communicates with the user-mode backdoor through IOCTL requests.

Once active, the rootkit can hide CoolClient processes, protect malware files and registry entries, and stop users or security products from tampering with the infection.

Kaspersky compared the approach with kernel-level capabilities previously found in the ToneShell backdoor.

Attackers can steal data and monitor victims

CoolClient already gives attackers several surveillance and system-control capabilities.

The backdoor can monitor keystrokes, capture clipboard data, harvest credentials, manage files, and perform system reconnaissance after compromising a device.

Adding a kernel driver makes those capabilities harder to disrupt because parts of the malware operate with deeper access to Windows.

Organizations should check for driver abuse

Kaspersky recommends checking endpoints for suspicious Microsoft Defender path exclusions and unexpected creation of services or files named msagent or media_updaten.

Administrators should also look for signs that malicious kernel drivers have been installed and ensure Microsoft’s kernel driver blocklists remain enabled and enforced.

The development comes as Windows security researchers continue to uncover new privilege escalation and protection bypass techniques. Microsoft recently patched the LegacyHive zero-day, although the same researcher later disclosed another exploit called ShieldBreak.

Researchers also recently disclosed a Download More RAM attack that can bypass Windows Security protections.

Via Neowin

More about the topics: microsoft, security, Windows

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages