Kaspersky: HoneyMyte Deploys Upgraded CoolClient Across Asia
Kaspersky’s GReAT has identified a new CoolClient variant linked to HoneyMyte (Mustang Panda) in a 2026 cyber-espionage campaign targeting Asia and Russia. The malware uses a signed kernel driver to evade detection, protect files and registry entries, and complicate remediation. Attackers first configured Microsoft Defender exclusions, created a fake Defender directory, and renamed a legitimate Sangfor executable to defender.exe. They then used a scheduled task with high privileges to launch the executable at startup. The malicious libngs.dll loaded by defender.exe ultimately triggered the CoolClient infection chain.
“The latest CoolClient variant represents a significant evolution of the malware. Rather than operating solely as a user-mode backdoor with plugin support, it now deploys and communicates with a kernel-mode driver that extends its capabilities beyond earlier versions. Through this driver, CoolClient can hide and protect processes, files and registry objects, as well as filter selected network information, making detection and analysis considerably more difficult. For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT.
Read the full report on securelist.com
Kaspersky GReAT recommends organizations monitor HoneyMyte indicators, deploy comprehensive Kaspersky Next protection, strengthen threat intelligence capabilities, and use managed security services such as Compromise Assessment, Managed Detection and Response, and Incident Response to identify, investigate, contain and remediate cyberthreats.
About the Global Research & Analysis Team
Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.