National Cyber Warfare Foundation (NCWF)

HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections


0 user ratings
2026-08-17 09:14:34
milo
Red Team (CNA)

HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. The development marks a notable escalation in the group’s post-compromise tradecraft, moving protection and evasion below the user-mode layer where many endpoint inspection […]


The post HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/honeymyte-upgrades-coolclient/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.