APT group HoneyMyte Upgrades CoolClient: The Backdoor Gets a Kernel-level Windows Rootkit

    Date: 08/26/2026

    Severity: Medium

    Summary

    CoolClient is a backdoor family linked to the HoneyMyte (Mustang Panda) APT group, targeting organizations across Asia and Russia. It supports capabilities such as keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. First documented by the team in 2022 and analyzed by another team in 2023, CoolClient has continued to evolve with new capabilities. A newer 2025 variant added clipboard theft and HTTP traffic interception to harvest credentials. The latest variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests. The driver improves stealth by hiding the backdoor process and protecting related files and registry entries from inspection or modification. The updated CoolClient variant and its associated driver have been observed in intrusions across several Asian countries, including Pakistan, Mongolia, and Myanmar.

    Indicators of Compromise (IOC) List

    Domains/URLs

    cloudtroe.giize.com

    employers.theworkpc.com

    freeread.casacam.net

    us.lenovoappstore.com

    sundanish.freeddns.org

    torinarlabs.webredirect.org

    news.dursamjbataar.org

    video.dursamjbataar.org

    black-popular.com

    whatismybestthing.com

    Hash

    2d7c8780e97409770a9d4f31c66c9d63

    9460E150E1981D5C165043520C5C12FE

    9717F005C5FB98E08D2AD983D88F94EE

    F518D8E5FE70D9090F6280C68A95998F

    EB79558B037669792652A816E2C669DE

    Filepath

    C:\Program Files\microsoft\windows defender\

    C:\Program Files\windows media player\mediares\

    C:\ProgramData\symantecdir\

    C:\ProgramData\virtualstore\

    C:\Windows\identitycrl\production\

    C:\Windows\serviceprofiles\networkservice\

    C:\Users\<user>\AppData\Local\viber24.8\

    C:\Users\<user>\AppData\Roaming\dsassistant\

    C:\Program Files\common files\microsoft shared\office14\

    C:\programdata\msdn\

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "sundanish.freeddns.org" or url like "sundanish.freeddns.org" or siteurl like "sundanish.freeddns.org" or domainname like "freeread.casacam.net" or url like "freeread.casacam.net" or siteurl like "freeread.casacam.net" or domainname like "torinarlabs.webredirect.org" or url like "torinarlabs.webredirect.org" or siteurl like "torinarlabs.webredirect.org" or domainname like "cloudtroe.giize.com" or url like "cloudtroe.giize.com" or siteurl like "cloudtroe.giize.com" or domainname like "whatismybestthing.com" or url like "whatismybestthing.com" or siteurl like "whatismybestthing.com" or domainname like "video.dursamjbataar.org" or url like "video.dursamjbataar.org" or siteurl like "video.dursamjbataar.org" or domainname like "employers.theworkpc.com" or url like "employers.theworkpc.com" or siteurl like "employers.theworkpc.com" or domainname like "black-popular.com" or url like "black-popular.com" or siteurl like "black-popular.com" or domainname like "us.lenovoappstore.com" or url like "us.lenovoappstore.com" or siteurl like "us.lenovoappstore.com" or domainname like "news.dursamjbataar.org" or url like "news.dursamjbataar.org" or siteurl like "news.dursamjbataar.org"

    Detection Query 2 :

    md5hash IN ("2d7c8780e97409770a9d4f31c66c9d63","EB79558B037669792652A816E2C669DE","9460E150E1981D5C165043520C5C12FE","9717F005C5FB98E08D2AD983D88F94EE","F518D8E5FE70D9090F6280C68A95998F")

    Detection Query 3 :

    datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "C:\Program Files\microsoft\windows defender" or objectname like "C:\Program Files\windows media player\mediares" or objectname like "C:\ProgramData\symantecdir" or objectname like "C:\ProgramData\virtualstore" or objectname like "C:\Windows\identitycrl\production" or objectname like "C:\Windows\serviceprofiles\networkservice" or objectname like "C:\Users\%\AppData\Local\viber24.8" or objectname like "C:\Users\%\AppData\Roaming\dsassistant" or objectname like "C:\Program Files\common files\microsoft shared\office14")

    Detection Query 4 :

    technologygroup = "EDR" and (objectname like "C:\Program Files\microsoft\windows defender" or objectname like "C:\Program Files\windows media player\mediares" or objectname like "C:\ProgramData\symantecdir" or objectname like "C:\ProgramData\virtualstore" or objectname like "C:\Windows\identitycrl\production" or objectname like "C:\Windows\serviceprofiles\networkservice" or objectname like "C:\Users\%\AppData\Local\viber24.8" or objectname like "C:\Users\%\AppData\Roaming\dsassistant" or objectname like "C:\Program Files\common files\microsoft shared\office14")

    Reference:    

    https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/                                   


    Tags

    MalwareThreat ActorMustang PandaAPTAsiaRussiaKeyloggerCredential HarvestingBackdoorPakistanMongoliaMyanmarRootkit

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags