Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Mustang Panda's Sophisticated Stealth: Unpacking the Latest CoolClient Backdoor


Mustang Panda's Sophisticated Stealth: Unpacking the Latest CoolClient Backdoor

  • The CoolClient backdoor has been updated with a new variant, dubbed "Mustang Panda," associated with the HoneyMyte threat group.
  • The Mustang Panda variant deploys a signed Windows kernel-mode rootkit, expanding its capabilities and allowing it to hide and protect malicious processes, files, and registry objects.
  • The rootkit provides elevated privileges and access to sensitive system resources, enabling the attackers to maintain a stealthy presence on compromised systems.
  • The CoolClient backdoor allows attackers to establish a persistent presence on systems, often used in conjunction with other malware and exploits to achieve more sophisticated goals.
  • The Mustang Panda variant includes 33 IOCTL handlers, providing stealth capabilities, hiding processes and kernel modules, manipulating registry values, and interacting with kernel notification callbacks.
  • The development marks a significant escalation in the threat posed by HoneyMyte, a threat actor known for its sophisticated and stealthy tactics.



  • In a recent development that highlights the evolving landscape of cyber threats, security researchers have identified a new variant of the CoolClient backdoor, associated with the notorious HoneyMyte threat group, known for its sophisticated and stealthy tactics. The latest CoolClient variant, dubbed "Mustang Panda," has been observed deploying a signed Windows kernel-mode rootkit that significantly expands the malware's capabilities, allowing it to hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information.

    According to Kaspersky, a Russian cybersecurity vendor, the threat actor known as HoneyMyte, or Mustang Panda, has been deploying this updated version of the CoolClient backdoor, which is accompanied by a signed Windows kernel-mode rootkit. This rootkit is designed to operate at the kernel level, providing the malware with elevated privileges and access to sensitive system resources.

    The CoolClient backdoor, itself, is a well-known piece of malware that has been associated with various threat actors in the past. It allows attackers to establish a persistent and stealthy presence on compromised systems, often used in conjunction with other malware and exploits to achieve more sophisticated goals.

    In this case, the Mustang Panda variant of CoolClient has been observed deploying the signed Windows kernel-mode rootkit, which is a significant departure from previous variants. The rootkit, which is digitally signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd., is designed to operate in the background, protecting malicious processes and files, and providing the attacker with a high degree of stealth and anonymity.

    The rootkit is deployed when CoolClient has full access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege. If these conditions are not met, the malware skips driver deployment and proceeds to the final-stage implant.

    Once loaded, the rootkit receives configuration from the CoolClient user-mode component through IOCTL requests. The three requests used by the analyzed sample during normal execution are - 0x222120, which registers the current CoolClient process as a trusted process with the driver; 0x2221E0, which passes the configured C2 IPv4 address to the driver; and 0x2220F0, which registers filesystem and registry paths that should be protected.

    The rootkit loads its stealth configuration from \REGISTRY\MACHINE\SYSTEM\RNG and uses separate configuration entries for directories, files, registry keys and values, and processes that should be hidden, protected, or ignored. It registers filesystem, registry, process, object, and image-load callbacks that use these entries when handling activity on the infected Windows system.

    The driver also implements process hiding by unlinking entries from the Windows active process list, uses a filesystem minifilter to deny access to protected files and directories, and registers a registry callback that removes protected keys and values from enumeration results and blocks attempts to modify or delete them.

    In addition to its stealth capabilities, the Mustang Panda variant of CoolClient also includes 33 IOCTL handlers, including functionality for hiding processes and kernel modules, manipulating registry values, and interacting with kernel notification callbacks.

    The researchers found that the analyzed CoolClient sample invoked only the three IOCTLs listed above during normal execution, with the remaining handlers not observed in use.

    Among the indicators shared by Kaspersky are the following hashes - 2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys; 9460E150E1981D5C165043520c5c12fe - msagent.sys; 9717f005c5fb98e08d2ad983d88f94ee - libngs.dll; F518D8E5FE70D9090F6280C68A95998F - libngs.dll.

    The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as The Hacker News reported in January 2026.

    Kaspersky had separately documented a different HoneyMyte kernel-mode rootkit in December 2025 that was used to load the ToneShell backdoor. The company said the overall design of the new CoolClient driver is comparable to the kernel-mode enhancements seen with ToneShell, while the CoolClient component exposes dedicated IOCTL handlers for direct communication with the user-mode backdoor.

    In conclusion, the Mustang Panda variant of CoolClient represents a significant escalation in the threat posed by HoneyMyte, a threat actor known for its sophisticated and stealthy tactics. The inclusion of a signed Windows kernel-mode rootkit in this variant underscores the evolving sophistication of threat actors in their use of malware and exploits to achieve more sophisticated goals.

    Mustang Panda's Sophisticated Stealth: Unpacking the Latest CoolClient Backdoor



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Mustang-Pandas-Sophisticated-Stealth-Unpacking-the-Latest-CoolClient-Backdoor-ehn.shtml

  • https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html


  • Published: Mon Aug 17 08:23:51 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us