Kaspersky identifies new variant linked to HoneyMyte APT
ISLAMABAD: A global cyber security company has discovered an updated malware that gives cyber attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia. According to the report of the company, Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also…
Global cybersecurity firm Kaspersky has identified a new malware variant that allows cybercriminals to gain remote access in attacks against organizations and government entities in several Asian and Russian countries. According to Kaspersky's Global Research and Analysis Team (GReAT), they have discovered a new CoolClient variant tied to the HoneyMyte Advanced Persistent Threat (APT), also known as Mustang Panda, involved in a 2026 cyber-espionage campaign across Asia and Russia.
The malware operates using a signed kernel driver, a type of software that runs deep within the system to conceal itself on infected Windows devices. During the observed campaign, the group utilized PlugX, another backdoor typically deployed following an initial breach, to deliver the CoolClient components.
The latest version of CoolClient is designed to operate discreetly, making removal and remediation more challenging. It employs a signed driver that runs deep within Windows, safeguarding related files and registry entries from inspection or modification and supporting the backdoor’s activities on the infected system. To retain access post-reboot, the attacker established a scheduled task that automatically launched defender.exe at startup with the highest local Windows privileges.
Upon execution, this task loaded a malicious libngs.dll file, initiating the CoolClient infection chain.
Security researcher Fareed Radzi from Kaspersky GReAT explained, "For the targeted organization, the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it."
Written by urgent.news from Business Recorder's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.