Actor
high
threat
Mustang Panda Deploys Signed Kernel-Mode Rootkit with CoolClient Backdoor
3 TTPs 4 IOCsThe threat actor HoneyMyte (Mustang Panda) is utilizing a signed kernel-mode rootkit named msagent.sys to provide stealth capabilities for its CoolClient backdoor, facilitating process, file, and network hiding on compromised Windows systems.
Windows
HoneyMyte
rootkit
backdoor
espionage
malware
3t
4i
high
threat
HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit
1 rule 3 TTPsThe HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.
Endpoint Secure
HoneyMyte
backdoor
rootkit
apt
windows
espionage
1r
3t