Kaspersky Reveals Chinese APT Mustang Panda Upgraded CoolClient Backdoor With Signed Kernel Rootkit Hiding Processes and Network Activity in Government Intrusions
Kaspersky's
Kaspersky's discovery of msagent.sys, a signed kernel-mode driver hiding CoolClient's processes, files, registry entries and command-and-control traffic from security tools, pushes incident response toward driver, service and registry-level inspection rather than conventional endpoint telemetry, an assessment resting on a single primary technical source echoed but not independently verified by other outlets. Government victims across Pakistan, Mongolia, Myanmar, India and Russia indicate HoneyMyte is fielding the capability in live espionage operations. Thirty of thirty-three IOCTL handlers remain unused in the analyzed sample, pointing to built-out capacity for kernel-level shellcode injection and arbitrary memory writes beyond current need. The 2013-2014 code-signing certificate ties the driver to a campaign-level pattern rather than a confirmed developer link, leaving open that it originates from a contractor serving multiple China-nexus operators rather than HoneyMyte exclusively.
4 sources
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit -
Kaspersky (Securelist) - Kaspersky: HoneyMyte deploys upgraded CoolClient backdoor in cyber-espionage campaign across Asia
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth -
The Hacker News - Mustang Panda Upgrades CoolClient With a Kernel Rootkit -
Security Affairs