news.mlab.sh
Back to the feed
threat-intel

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

High
Image: The Hacker News
Summary

The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a driver named msagent.sys, allows the CoolClient backdoor to hide processes, files, registry objects, and C2 network information, effectively evading detection. The update follows previous HoneyMyte activity targeting Myanmar and Pakistan, utilizing PlugX to deploy CoolClient and a ToneShell rootkit. The rootkit leverages IOCTL requests for communication between the kernel-mode driver and the user-mode CoolClient backdoor.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.