Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a driver named msagent.sys, allows the CoolClient backdoor to hide processes, files, registry objects, and C2 network information, effectively evading detection. The update follows previous HoneyMyte activity targeting Myanmar and Pakistan, utilizing PlugX to deploy CoolClient and a ToneShell rootkit. The rootkit leverages IOCTL requests for communication between the kernel-mode driver and the user-mode CoolClient backdoor.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
