Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CoolClient backdoor goes deeper: Windows kernel rootkit added

0
Medium
Published: 08/14/2026 (08/14/2026, 10:50:02 UTC)
Source: AlienVault OTX General

Description

The HoneyMyte APT group (Mustang Panda) has enhanced its CoolClient backdoor by adding a signed Windows kernel-mode rootkit driver (msagent.sys). This driver operates as a Windows service and provides stealth capabilities such as hiding processes, protecting files and registry entries, and filtering network traffic. The malware uses DLL sideloading via a legitimate Sangfor application, persists through scheduled tasks and AutoRun entries, and bypasses User Account Control (UAC). CoolClient injects into synchost.exe and communicates with the kernel driver using IOCTL requests. The rootkit hooks Nsiproxy to filter command and control (C2) addresses. Initial infection vectors include PlugX malware. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 12:41:19 UTC

Technical Analysis

HoneyMyte (Mustang Panda) has significantly upgraded the CoolClient backdoor by integrating a signed kernel-mode driver (msagent.sys) that runs as a Windows service. This kernel rootkit enables advanced stealth features such as process hiding, file and registry protection, and network traffic filtering by hooking Nsiproxy to filter C2 addresses. The multi-stage infection chain involves DLL sideloading through a legitimate Sangfor application, persistence via scheduled tasks and AutoRun registry entries, and UAC bypass techniques. CoolClient injects into the synchost.exe process and communicates with the kernel driver through IOCTL requests. The initial infection vector is PlugX malware. Confirmed victim countries include Myanmar, Mongolia, Pakistan, and Russia.

Potential Impact

The integration of a signed kernel-mode rootkit driver allows the CoolClient backdoor to operate with high stealth and persistence on infected Windows systems. It can hide processes, protect malicious files and registry keys from detection or removal, and filter network traffic to evade network-based detection of command and control communications. This elevates the threat's ability to maintain long-term access and complicates detection and remediation efforts. The use of UAC bypass and DLL sideloading further enhances its ability to evade security controls and maintain persistence.

Defensive Guidance

No official patch or remediation is indicated in the provided information. Since this is malware deployed by an APT group, mitigation should focus on detection and removal using updated endpoint protection solutions capable of detecting kernel-mode rootkits and associated indicators of compromise. Monitoring for the listed domains and file hashes can aid detection. Network defenses should look for unusual Nsiproxy hooks or filtered C2 traffic. Given the advanced stealth techniques, full system reimaging may be necessary upon detection. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"]
Adversary
MUSTANG PANDA
Pulse Id
6a7ef2da146fb06724520eb4
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainvideo.dursamjbataar.org
domainsundanish.freeddns.org
domainemployers.theworkpc.com
domainfreeread.casacam.net
domainus.lenovoappstore.com
domaintorinarlabs.webredirect.org
domainnews.dursamjbataar.org
domainblack-popular.com
domainwhatismybestthing.com

Hash

ValueDescriptionCopy
hashf518d8e5fe70d9090f6280c68a95998f
hash2d7c8780e97409770a9d4f31c66c9d63
hash9460e150e1981d5c165043520c5c12fe
hash9717f005c5fb98e08d2ad983d88f94ee
hasheb79558b037669792652a816e2c669de
hashb813c4d9be3ba88159f1f83ce805f8b730b38dde
hashee72ae4cc869affddab11647e95bab9c5691c9fc76dcb4b31650ff504da29156

Threat ID: 6a7efb55bf8831d539f37fa0

Added to database: 08/14/2026, 11:26:13 UTC

Last enriched: 08/14/2026, 12:41:19 UTC

Last updated: 08/15/2026, 00:56:43 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses