{
  "id": 2275132,
  "title": "Kaspersky identifies new variant linked to HoneyMyte APT",
  "url": "https://urgent.news/2026/08/21/kaspersky-identifies-new-variant-linked-to-honeymyte-apt",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T01:38:30.000Z",
  "source": {
    "name": "Business Recorder",
    "slug": "business-recorder",
    "url": "https://www.brecorder.com/news/40435885/kaspersky-identifies-new-variant-linked-to-honeymyte-apt"
  },
  "original_language": "en",
  "account": "Global cybersecurity firm Kaspersky has identified a new malware variant that allows cybercriminals to gain remote access in attacks against organizations and government entities in several Asian and Russian countries. According to Kaspersky's Global Research and Analysis Team (GReAT), they have discovered a new CoolClient variant tied to the HoneyMyte Advanced Persistent Threat (APT), also known as Mustang Panda, involved in a 2026 cyber-espionage campaign across Asia and Russia.\n\nThe malware operates using a signed kernel driver, a type of software that runs deep within the system to conceal itself on infected Windows devices. During the observed campaign, the group utilized PlugX, another backdoor typically deployed following an initial breach, to deliver the CoolClient components.\n\nThe latest version of CoolClient is designed to operate discreetly, making removal and remediation more challenging. It employs a signed driver that runs deep within Windows, safeguarding related files and registry entries from inspection or modification and supporting the backdoor’s activities on the infected system. To retain access post-reboot, the attacker established a scheduled task that automatically launched defender.exe at startup with the highest local Windows privileges. Upon execution, this task loaded a malicious libngs.dll file, initiating the CoolClient infection chain.\n\nSecurity researcher Fareed Radzi from Kaspersky GReAT explained, \"For the targeted organization, the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it.\"",
  "summary": "ISLAMABAD: A global cyber security company has discovered an updated malware that gives cyber attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia. According to the report of the company, Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}