CoolClient backdoor goes deeper: Windows kernel rootkit added
The HoneyMyte APT group (Mustang Panda) has enhanced its CoolClient backdoor by adding a signed Windows kernel-mode rootkit driver (msagent.sys). This driver operates as a Windows service and provides stealth capabilities such as hiding processes, protecting files and registry entries, and filtering network traffic. The malware uses DLL sideloading via a legitimate Sangfor application, persists through scheduled tasks and AutoRun entries, and bypasses User Account Control (UAC). CoolClient injects into synchost.exe and communicates with the kernel driver using IOCTL requests. The rootkit hooks Nsiproxy to filter command and control (C2) addresses. Initial infection vectors include PlugX malware. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia.
AI Analysis
Technical Summary
HoneyMyte (Mustang Panda) has significantly upgraded the CoolClient backdoor by integrating a signed kernel-mode driver (msagent.sys) that runs as a Windows service. This kernel rootkit enables advanced stealth features such as process hiding, file and registry protection, and network traffic filtering by hooking Nsiproxy to filter C2 addresses. The multi-stage infection chain involves DLL sideloading through a legitimate Sangfor application, persistence via scheduled tasks and AutoRun registry entries, and UAC bypass techniques. CoolClient injects into the synchost.exe process and communicates with the kernel driver through IOCTL requests. The initial infection vector is PlugX malware. Confirmed victim countries include Myanmar, Mongolia, Pakistan, and Russia.
Potential Impact
The integration of a signed kernel-mode rootkit driver allows the CoolClient backdoor to operate with high stealth and persistence on infected Windows systems. It can hide processes, protect malicious files and registry keys from detection or removal, and filter network traffic to evade network-based detection of command and control communications. This elevates the threat's ability to maintain long-term access and complicates detection and remediation efforts. The use of UAC bypass and DLL sideloading further enhances its ability to evade security controls and maintain persistence.
Mitigation Recommendations
No official patch or remediation is indicated in the provided information. Since this is malware deployed by an APT group, mitigation should focus on detection and removal using updated endpoint protection solutions capable of detecting kernel-mode rootkits and associated indicators of compromise. Monitoring for the listed domains and file hashes can aid detection. Network defenses should look for unusual Nsiproxy hooks or filtered C2 traffic. Given the advanced stealth techniques, full system reimaging may be necessary upon detection. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for remediation guidance.
Affected Countries
Myanmar, Mongolia, Pakistan, Russia
Indicators of Compromise
- domain: video.dursamjbataar.org
- domain: sundanish.freeddns.org
- hash: f518d8e5fe70d9090f6280c68a95998f
- hash: 2d7c8780e97409770a9d4f31c66c9d63
- hash: 9460e150e1981d5c165043520c5c12fe
- hash: 9717f005c5fb98e08d2ad983d88f94ee
- hash: eb79558b037669792652a816e2c669de
- domain: employers.theworkpc.com
- domain: freeread.casacam.net
- domain: us.lenovoappstore.com
- domain: torinarlabs.webredirect.org
- domain: news.dursamjbataar.org
- domain: black-popular.com
- domain: whatismybestthing.com
- hash: b813c4d9be3ba88159f1f83ce805f8b730b38dde
- hash: ee72ae4cc869affddab11647e95bab9c5691c9fc76dcb4b31650ff504da29156
CoolClient backdoor goes deeper: Windows kernel rootkit added
Description
The HoneyMyte APT group (Mustang Panda) has enhanced its CoolClient backdoor by adding a signed Windows kernel-mode rootkit driver (msagent.sys). This driver operates as a Windows service and provides stealth capabilities such as hiding processes, protecting files and registry entries, and filtering network traffic. The malware uses DLL sideloading via a legitimate Sangfor application, persists through scheduled tasks and AutoRun entries, and bypasses User Account Control (UAC). CoolClient injects into synchost.exe and communicates with the kernel driver using IOCTL requests. The rootkit hooks Nsiproxy to filter command and control (C2) addresses. Initial infection vectors include PlugX malware. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
HoneyMyte (Mustang Panda) has significantly upgraded the CoolClient backdoor by integrating a signed kernel-mode driver (msagent.sys) that runs as a Windows service. This kernel rootkit enables advanced stealth features such as process hiding, file and registry protection, and network traffic filtering by hooking Nsiproxy to filter C2 addresses. The multi-stage infection chain involves DLL sideloading through a legitimate Sangfor application, persistence via scheduled tasks and AutoRun registry entries, and UAC bypass techniques. CoolClient injects into the synchost.exe process and communicates with the kernel driver through IOCTL requests. The initial infection vector is PlugX malware. Confirmed victim countries include Myanmar, Mongolia, Pakistan, and Russia.
Potential Impact
The integration of a signed kernel-mode rootkit driver allows the CoolClient backdoor to operate with high stealth and persistence on infected Windows systems. It can hide processes, protect malicious files and registry keys from detection or removal, and filter network traffic to evade network-based detection of command and control communications. This elevates the threat's ability to maintain long-term access and complicates detection and remediation efforts. The use of UAC bypass and DLL sideloading further enhances its ability to evade security controls and maintain persistence.
Defensive Guidance
No official patch or remediation is indicated in the provided information. Since this is malware deployed by an APT group, mitigation should focus on detection and removal using updated endpoint protection solutions capable of detecting kernel-mode rootkits and associated indicators of compromise. Monitoring for the listed domains and file hashes can aid detection. Network defenses should look for unusual Nsiproxy hooks or filtered C2 traffic. Given the advanced stealth techniques, full system reimaging may be necessary upon detection. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for remediation guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"]
- Adversary
- MUSTANG PANDA
- Pulse Id
- 6a7ef2da146fb06724520eb4
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainvideo.dursamjbataar.org | — | |
domainsundanish.freeddns.org | — | |
domainemployers.theworkpc.com | — | |
domainfreeread.casacam.net | — | |
domainus.lenovoappstore.com | — | |
domaintorinarlabs.webredirect.org | — | |
domainnews.dursamjbataar.org | — | |
domainblack-popular.com | — | |
domainwhatismybestthing.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashf518d8e5fe70d9090f6280c68a95998f | — | |
hash2d7c8780e97409770a9d4f31c66c9d63 | — | |
hash9460e150e1981d5c165043520c5c12fe | — | |
hash9717f005c5fb98e08d2ad983d88f94ee | — | |
hasheb79558b037669792652a816e2c669de | — | |
hashb813c4d9be3ba88159f1f83ce805f8b730b38dde | — | |
hashee72ae4cc869affddab11647e95bab9c5691c9fc76dcb4b31650ff504da29156 | — |
Threat ID: 6a7efb55bf8831d539f37fa0
Added to database: 08/14/2026, 11:26:13 UTC
Last enriched: 08/14/2026, 12:41:19 UTC
Last updated: 08/15/2026, 00:56:43 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.