Threats Tagged 'honeymyte'
View all threats tagged with 'honeymyte'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'honeymyte'
Click on any threat for detailed analysis and mitigation recommendations
CoolClient backdoor goes deeper: Windows kernel rootkit added 0 The HoneyMyte APT group (Mustang Panda) has enhanced its CoolClient backdoor by adding a signed Windows kernel-mode rootkit driver (msagent.sys). This driver operates as a Windows service and provides stealth capabilities such as hiding processes, protecting files and registry entries, and filtering network traffic. The malware uses DLL sideloading via a legitimate Sangfor application, persists through scheduled tasks and AutoRun entries, and bypasses User Account Control (UAC). CoolClient injects into synchost.exe and communicates with the kernel driver using IOCTL requests. The rootkit hooks Nsiproxy to filter command and control (C2) addresses. Initial infection vectors include PlugX malware. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia. Join the discussion | AlienVault OTX General | 08/14/2026, 10:50:02 UTC Added: 08/14/2026, 11:26:13 UTC |
Showing 1 to 1 of 1 result