Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mustang Panda’s Enhanced CoolClient and Rootkit Tactics

Mustang Panda’s Enhanced CoolClient and Rootkit Tactics

Posted on August 18, 2026 By CWS

Mustang Panda, also known as HoneyMyte, has integrated a signed Windows kernel-mode rootkit with its CoolClient backdoor, enhancing its ability to obscure malicious processes and data. This development was reported by Kaspersky, a Russian cybersecurity firm, which identified the presence of CoolClient in various countries, including Myanmar, Mongolia, Pakistan, and Russia. The backdoor is typically deployed post-PlugX infection, suggesting an advanced multi-stage attack strategy.

Stealth Techniques in Malware Deployment

The updated CoolClient utilizes a kernel component that activates upon gaining full access to the Windows Service Control Manager, coupled with the SeTcbPrivilege privilege. This allows it to bypass driver deployment restrictions. If these conditions are unmet, the malware skips to the final stage of its implant sequence. Kaspersky has made public several indicators of compromise, such as file hashes and C2 domains, to aid in detection efforts.

Kaspersky’s analysis highlights that while the execution flow of CoolClient remains as previously documented, the introduction of a new kernel-mode driver significantly boosts its stealth capabilities. This driver can be installed as a Windows service and is managed via IOCTL requests from the user-mode backdoor, facilitating operations like keylogging and system reconnaissance.

PlugX: The Initial Vector

In a targeted operation in Myanmar, PlugX was used to initiate the compromise, setting the stage for CoolClient deployment. The threat actor employed techniques like Microsoft Defender exclusions and DLL sideloading to obscure activities and maintain persistence. By renaming legitimate executables and scheduling tasks, the malware ensures its continuity across system reboots.

Execution commences with the loading of a malicious DLL, which decrypts and executes subsequent components. These components are responsible for a variety of malicious activities, including registry modifications and User Account Control bypasses. The malware’s ability to inject itself into processes like synchost.exe underscores its sophistication in evading detection.

Rootkit Capabilities and Impact

The rootkit, identified as msagent.sys, is digitally signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd., although no direct links have been found between older malicious drivers and current activities. Once operational, the rootkit handles configuration via CoolClient through IOCTL requests, managing tasks like process protection and filesystem access.

This rootkit employs numerous techniques to maintain stealth, such as process hiding and registry manipulation. It filters network information to shield C2 communications from user-mode scrutiny. Despite the presence of extensive IOCTL handlers, only a select few were utilized in the observed samples, indicating targeted functionality deployment.

The continuous evolution of CoolClient and its integration with sophisticated rootkits poses significant challenges for cybersecurity defenders. As Mustang Panda refines its tools, understanding and mitigating such threats becomes increasingly critical for organizations worldwide.

The Hacker News Tags:C2 communications, CoolClient, cyber attack, cyber threats, Cybersecurity, digital signature, HoneyMyte, IOCTL, Kaspersky, kernel-mode driver, Malware, Mustang Panda, PlugX, Rootkit, Windows security

Post navigation

Previous Post: Cavern Framework Evolves with New DNS and Google Apps Integration
Next Post: Chrome DevTools Enables Session Hijacking in Windows

Related Posts

Critical Dify Vulnerabilities Could Expose AI Data Critical Dify Vulnerabilities Could Expose AI Data The Hacker News
New PumaBot Botnet Targets Linux IoT Devices to Steal SSH Credentials and Mine Crypto New PumaBot Botnet Targets Linux IoT Devices to Steal SSH Credentials and Mine Crypto The Hacker News
SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported The Hacker News
Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now The Hacker News
Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic The Hacker News
How Leading CISOs are Getting Budget Approval How Leading CISOs are Getting Budget Approval The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CTM360 Exposes Over 3,000 Phishing URLs in Job Scams
  • Chrome DevTools Enables Session Hijacking in Windows
  • Mustang Panda’s Enhanced CoolClient and Rootkit Tactics
  • Cavern Framework Evolves with New DNS and Google Apps Integration
  • Critical Flaw in Forminator Plugin Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CTM360 Exposes Over 3,000 Phishing URLs in Job Scams
  • Chrome DevTools Enables Session Hijacking in Windows
  • Mustang Panda’s Enhanced CoolClient and Rootkit Tactics
  • Cavern Framework Evolves with New DNS and Google Apps Integration
  • Critical Flaw in Forminator Plugin Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark