Skip to main content

Kaspersky: HoneyMyte deploys upgraded CoolClient backdoor in cyber-espionage campaign across Asia

14 August 2026

Kaspersky GReAT has discovered an updated CoolClient backdoor, a type of malware that gives attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia.

Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also known as Mustang Panda, in a 2026 cyber-espionage campaign across Asia and Russia. The malware uses a signed kernel driver, software that runs deep in the system to hide on infected Windows devices. In the observed campaign the actor used PlugX, another backdoor commonly deployed after an initial breach, to deliver the CoolClient components.

The latest CoolClient variant is designed to operate with a stealthy profile and make remediation more difficult. It deploys a signed driver that runs deep within Windows to help hide the malware’s presence, protect related files and registry entries from inspection or modification and support the backdoor’s activity on the infected system.

Before deploying the malware, the attacker configured Microsoft Defender to ignore a specific folder and file. These exclusions covered a fake Windows Defender directory and a renamed executable, defender.exe. The attacker then created the fake directory, copied the CoolClient files into it, and renamed a legitimate Sangfor program to defender.exe so it could be used to load malicious code.

To maintain access after a reboot, the attacker created a scheduled task that launched defender.exe automatically at startup with the highest local Windows privileges. When executed, it loaded a malicious libngs.dll file triggering the CoolClient infection chain.

“The latest CoolClient variant represents a significant evolution of the malware. Rather than operating solely as a user-mode backdoor with plugin support, it now deploys and communicates with a kernel-mode driver that extends its capabilities beyond earlier versions. Through this driver, CoolClient can hide and protect processes, files and registry objects, as well as filter selected network information, making detection and analysis considerably more difficult. For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT.

Read the full report on securelist.com

To stay safe and not become a victim of the new CoolClient version, Kaspersky GReAT experts recommend organizations:

  • Remain highly vigilant against the deployment of HoneyMyte IoCs and other tools presented in the report.
  • Use all-encompassing solutions from theKaspersky Next product line that provide real-time protection, threat visibility, investigation and response capabilities of EPP, EDR and XDR. Depending on your current needs and available resources, you can choose the most relevant solution within this product line and easily migrate to another one if your cybersecurity requirements are changing.
  • Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organization. The latestKaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.
  • If your company lacks cybersecurity expertise, adopt managed security services by Kaspersky such as Compromise Assessment,Managed Detection and Response and/orIncident Response which cover the entire incident management cycle – from threat identification to continuous protection and remediation

About the Global Research & Analysis Team
Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.

Kaspersky: HoneyMyte deploys upgraded CoolClient backdoor in cyber-espionage campaign across Asia

Kaspersky GReAT has discovered an updated CoolClient backdoor, a type of malware that gives attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases