Kaspersky GReAT has discovered an updated CoolClient backdoor, a type of malware that gives attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia.
Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also known as Mustang Panda, in a 2026 cyber-espionage campaign across Asia and Russia. The malware uses a signed kernel driver, software that runs deep in the system to hide on infected Windows devices. In the observed campaign the actor used PlugX, another backdoor commonly deployed after an initial breach, to deliver the CoolClient components.
The latest CoolClient variant is designed to operate with a stealthy profile and make remediation more difficult. It deploys a signed driver that runs deep within Windows to help hide the malware’s presence, protect related files and registry entries from inspection or modification and support the backdoor’s activity on the infected system.
Before deploying the malware, the attacker configured Microsoft Defender to ignore a specific folder and file. These exclusions covered a fake Windows Defender directory and a renamed executable, defender.exe. The attacker then created the fake directory, copied the CoolClient files into it, and renamed a legitimate Sangfor program to defender.exe so it could be used to load malicious code.
To maintain access after a reboot, the attacker created a scheduled task that launched defender.exe automatically at startup with the highest local Windows privileges. When executed, it loaded a malicious libngs.dll file triggering the CoolClient infection chain.
“The latest CoolClient variant represents a significant evolution of the malware. Rather than operating solely as a user-mode backdoor with plugin support, it now deploys and communicates with a kernel-mode driver that extends its capabilities beyond earlier versions. Through this driver, CoolClient can hide and protect processes, files and registry objects, as well as filter selected network information, making detection and analysis considerably more difficult. For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT.
Read the full report on securelist.com
To stay safe and not become a victim of the new
CoolClient version, Kaspersky GReAT experts recommend organizations:
- Remain highly vigilant against the deployment of HoneyMyte IoCs and other tools presented in the report.
- Use all-encompassing solutions from theKaspersky Next product line that provide real-time protection, threat visibility, investigation and response capabilities of EPP, EDR and XDR. Depending on your current needs and available resources, you can choose the most relevant solution within this product line and easily migrate to another one if your cybersecurity requirements are changing.
- Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organization. The latestKaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.
- If your company lacks cybersecurity expertise, adopt managed security services by Kaspersky such as Compromise Assessment,Managed Detection and Response and/orIncident Response which cover the entire incident management cycle – from threat identification to continuous protection and remediation
About the Global Research & Analysis Team
Established in 2008, Global Research & Analysis Team (GReAT)
operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage
campaigns, major malware, ransomware and underground cyber-criminal trends
across the world. Today GReAT consists of 35+ experts working globally – in
Europe, Russia, Latin America, Asia and the Middle East. Talented security
professionals provide company leadership in anti-malware research and
innovation, bringing unrivaled expertise, passion and curiosity to the discovery
and analysis of cyberthreats.