Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
- ID
- 14787
- Status
- new
- Published
- 14 Aug 2026, 9:08 PM
- Fetched
- 17 Aug 2026, 8:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan,
Summary
No summary yet. It will appear after the daemon summarizes this item.