Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Evolution of CoolClient: A Sophisticated Kernel Rootkit and Its Implications for Cybersecurity


Recent research by Kaspersky has revealed a significant upgrade to the CoolClient kernel rootkit, which has evolved to deploy a signed kernel-mode driver that can hide processes, files, and registry entries, making it a formidable tool for attackers. This development has significant implications for cybersecurity, as it highlights the importance of staying vigilant in the face of emerging threats and the need for continuous monitoring and analysis to keep pace with the evolving cybersecurity landscape.

  • CoolClient, a sophisticated kernel rootkit, has been enhanced with significant capabilities.
  • The malware deploys a signed kernel-mode driver, "msagent.sys", to hide processes, files, and registry entries.
  • The driver contains 33 IOCTL handlers, although only three are used, revealing its extensive capabilities.
  • The driver uses a digital signature linked to Nanjing Ranyi Technology Co., Ltd., with a certificate valid from 2013 to 2014.
  • The malware's implications are far-reaching, making detection and analysis considerably more difficult for defenders.
  • The CoolClient variant represents a significant evolution of the malware, highlighting the importance of staying vigilant in the face of emerging threats.



  • The world of cybersecurity has witnessed the emergence of a sophisticated kernel rootkit known as CoolClient, which has undergone significant enhancements in its capabilities. According to recent findings by Kaspersky, a leading cybersecurity firm, CoolClient has upgraded its kernel-mode driver, dubbed "msagent.sys," to enhance its stealth and persistence in the Windows ecosystem.

    CoolClient, a notorious piece of malware, first appeared publicly in 2022 through Sophos research and was later analyzed by Trend Micro in 2023. Its capabilities were further expanded in 2025, when it gained clipboard theft and HTTP traffic interception for credential harvesting. The latest version of CoolClient has taken its sophistication to the next level by incorporating a signed kernel-mode driver that can hide processes, files, and registry entries, making it a formidable tool for attackers.

    The new variant of CoolClient deploys the "msagent.sys" driver as a Windows service, which communicates with it through IOCTL requests. This allows the malware to hide its presence, block security tools from accessing or terminating protected components, and even filter selected network information. The driver contains 33 IOCTL handlers, although the analyzed CoolClient sample normally uses only three. The unused handlers reveal the extent of the driver's capabilities, including hiding kernel modules, injecting shellcode, terminating processes, and manipulating registry values.

    The CoolClient kernel-mode driver uses a digital signature linked to Nanjing Ranyi Technology Co., Ltd., with a certificate valid from 2013 to 2014. Kaspersky also found older malicious drivers using the same certificate, but no direct link to CoolClient. The driver includes additional functions for manipulating kernel components, even if they were not observed in use.

    The implications of this development are far-reaching, as CoolClient can now hide and protect processes, files, and registry objects, as well as filter selected network information. This makes detection and analysis considerably more difficult for defenders. Investigators must now examine drivers, services, registry changes, and unusual network activity to uncover the malware's presence.

    The latest CoolClient variant represents a significant evolution of the malware, as it now deploys and communicates with a kernel-mode driver that extends its capabilities beyond earlier versions. This highlights the importance of staying vigilant in the face of emerging threats and the need for continuous monitoring and analysis to keep pace with the evolving cybersecurity landscape.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Evolution-of-CoolClient-A-Sophisticated-Kernel-Rootkit-and-Its-Implications-for-Cybersecurity-ehn.shtml

  • https://securityaffairs.com/197274/uncategorized/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html

  • https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html

  • https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html


  • Published: Sun Aug 16 13:05:54 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us