THREATOPS
THREAT OPSThreat News › APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

highsecurelistPublished 2026-08-14

<p><img alt="" class="attachment-securelist-huge-promo size-securelist-huge-promo wp-post-image" height="400" src="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/08/12120025/honeymyte-driver-overview_1-990x400.jpg" width="990" /></p><h2 id="introduction">Introduction</h2> <p>CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda)

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/