{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/honeymyte/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["HoneyMyte"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Endpoint Secure"],"_cs_severities":["high"],"_cs_tags":["backdoor","rootkit","apt","windows","espionage"],"_cs_type":"threat","_cs_vendors":["Sangfor"],"content_html":"\u003cp\u003eThe HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor, introducing a kernel-mode rootkit driver to enhance stealth. The updated malware utilizes DLL sideloading via legitimate Sangfor executables to achieve initial execution and persistence. The most notable evolution is the deployment of a signed kernel-mode driver, which acts as a Windows service and communicates with the user-mode backdoor via IOCTL requests. This driver provides rootkit capabilities, specifically hiding malicious processes, files, and registry entries from security tools and analysts.\u003c/p\u003e\n\u003cp\u003eThe intrusion chain involves the use of PlugX as an initial post-compromise implant to facilitate the deployment of CoolClient components. The threat actor actively modifies Microsoft Defender exclusions to evade detection before establishing persistence through scheduled tasks running with SYSTEM privileges. The malware continues its multi-stage loading process, involving heavily obfuscated components that decrypt and execute the final-stage C2 implant, now renamed to 'cert.ini'. This update, observed in intrusions across Asia, signifies a shift toward deeper kernel-level integration for long-term espionage operations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained using a PlugX implant to download and stage CoolClient components.\u003c/li\u003e\n\u003cli\u003eThe actor adds directory and file exclusions to Microsoft Defender using 'wmic' to allow the malicious 'defender.exe' (a renamed Sangfor executable) to run undetected.\u003c/li\u003e\n\u003cli\u003eA scheduled task is created under the name 'Microsoft\\Windows\\Windows Defender Advanced Threat Protection Service' to execute 'defender.exe' with SYSTEM privileges at startup.\u003c/li\u003e\n\u003cli\u003e'defender.exe' performs DLL sideloading by loading the malicious 'libngs.dll'.\u003c/li\u003e\n\u003cli\u003e'libngs.dll' executes its DllMain routine to decrypt and load 'loadcert.ini' into memory.\u003c/li\u003e\n\u003cli\u003eThe second-stage loader 'loadcert.ini' decrypts 'time.ini', deploys the kernel-mode driver as a Windows service, and injects the final-stage 'cert.ini' implant into 'synchost.exe'.\u003c/li\u003e\n\u003cli\u003eThe driver enables rootkit features by intercepting and filtering system calls via IOCTL requests to mask the presence of CoolClient.\u003c/li\u003e\n\u003cli\u003eThe final-stage implant establishes C2 communication to perform espionage activities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe updated CoolClient backdoor allows HoneyMyte to maintain persistent, long-term access to compromised systems in Asia, including Pakistan, Mongolia, and Myanmar. The kernel-mode rootkit significantly hampers incident response and forensic analysis by concealing the malware's footprint, potentially leading to prolonged undetected data exfiltration and cyber-espionage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy Sigma rules to detect the creation of suspicious Microsoft Defender exclusions via WMI.\u003c/li\u003e\n\u003cli\u003eMonitor scheduled tasks for entries that execute binaries from non-standard or unauthorized directories, specifically targeting the identified 'Windows Defender' folder path masquerading.\u003c/li\u003e\n\u003cli\u003eImplement endpoint detection for unauthorized loading of kernel drivers, specifically focusing on drivers not signed by known, trusted vendors.\u003c/li\u003e\n\u003cli\u003eHunt for the presence of the identified CoolClient component filenames ('loadcert.ini', 'cert.ini', 'time.ini', 'libngs.dll') within the environment.\u003c/li\u003e\n\u003cli\u003eAudit system services and drivers for unexpected additions or modifications, particularly those interacting with legitimate process names like 'synchost.exe'.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-14T14:03:05Z","date_published":"2026-08-14T14:03:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-coolclient-rootkit/","summary":"The HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.","title":"HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit","url":"https://feed.craftedsignal.io/briefs/2026-08-coolclient-rootkit/"}],"language":"en","title":"CraftedSignal Threat Feed - HoneyMyte","version":"https://jsonfeed.org/version/1.1"}