Adversary Intelligence — 2026-08-17

Kaspersky Reveals Chinese APT Mustang Panda Upgraded CoolClient Backdoor With Signed Kernel Rootkit Hiding Processes and Network Activity in Government Intrusions

BLUFMustang Panda's investment in kernel-level concealment across five countries signals a maturing espionage platform whose unused driver capabilities likely presage more aggressive host manipulation in future intrusions.

Kaspersky's GReAT team reported that HoneyMyte, also tracked as Mustang Panda, upgraded its CoolClient backdoor with a signed kernel-mode Windows driver, msagent.sys, installed as a service and controlled through IOCTL requests 12. The driver hides and protects CoolClient's processes, files and registry entries from inspection and filters the malware's command-and-control IP address from network data returned to security tools 13. Kaspersky documented the variant in intrusions across Pakistan, Mongolia and Myanmar, with victims also in India and Russia including confirmed government entities; in the Myanmar case, HoneyMyte deployed PlugX before installing CoolClient 123. The driver carries a digital signature issued to Nanjing Ranyi Technology Co., Ltd. valid from 2013 to 2014 and contains 33 IOCTL handlers, of which the analyzed sample used only three 34. The driver's embedded program database path references a facility transliterated as "Nanjing Laboratory" and a developer name rendered as Zhang Xuejie Yunnan m, and Kaspersky separately found older malicious drivers signed with the same certificate dating to around 2013 with no confirmed link established to CoolClient activity 34.

Analysis
Kaspersky's discovery of msagent.sys, a signed kernel-mode driver hiding CoolClient's processes, files, registry entries and command-and-control traffic from security tools, pushes incident response toward driver, service and registry-level inspection rather than conventional endpoint telemetry, an assessment resting on a single primary technical source echoed but not independently verified by other outlets. Government victims across Pakistan, Mongolia, Myanmar, India and Russia indicate HoneyMyte is fielding the capability in live espionage operations. Thirty of thirty-three IOCTL handlers remain unused in the analyzed sample, pointing to built-out capacity for kernel-level shellcode injection and arbitrary memory writes beyond current need. The 2013-2014 code-signing certificate ties the driver to a campaign-level pattern rather than a confirmed developer link, leaving open that it originates from a contractor serving multiple China-nexus operators rather than HoneyMyte exclusively.
4 sources
  1. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit - Kaspersky (Securelist)
  2. Kaspersky: HoneyMyte deploys upgraded CoolClient backdoor in cyber-espionage campaign across Asia
  3. Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth - The Hacker News
  4. Mustang Panda Upgrades CoolClient With a Kernel Rootkit - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE