Kaspersky: HoneyMyte deploys upgraded CoolClient across Asia

  • DCV Desk
  • 06 Sep, 2026, 04:29 PM
Kaspersky: HoneyMyte deploys upgraded CoolClient across Asia Photo: Courtesy
ad
Kaspersky’s GReAT has identified a new CoolClient variant linked to HoneyMyte (Mustang Panda) in a 2026 cyber-espionage campaign targeting Asia and Russia. The malware uses a signed kernel driver to evade detection, protect files and registry entries, and complicate remediation. Attackers first configured Microsoft Defender exclusions, created a fake Defender directory, and renamed a legitimate Sangfor executable to defender.exe. They then used a scheduled task with high privileges to launch the executable at startup. The malicious libngs.dll loaded by defender.exe ultimately triggered the CoolClient infection chain, a press release said.
“The latest CoolClient variant represents a significant evolution of the malware. Rather than operating solely as a user-mode backdoor with plugin support, it now deploys and communicates with a kernel-mode driver that extends its capabilities beyond earlier versions. Through this driver, CoolClient can hide and protect processes, files and registry objects, as well as filter selected network information, making detection and analysis considerably more difficult. For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT.
Read the full report on securelist.com, Kaspersky GReAT recommends organizations monitor HoneyMyte indicators, deploy comprehensive Kaspersky Next protection, strengthen threat intelligence capabilities, and use managed security services such as Compromise Assessment, Managed Detection and Response, and Incident Response to identify, investigate, contain and remediate cyberthreats.


Comment