#8
The Hacker News
general
August 14, 2026 at 13:08 UTC
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
By [email protected] (The Hacker News)
AI Summary
Mustang Panda (HoneyMyte) has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit capable of hiding malicious processes, files, registry keys, and C2 network traffic, with victims identified in Myanmar, Mongolia, and Pakistan. The use of a legitimately signed rootkit significantly raises the bar for detection on affected endpoints.
Relevance score: 76.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →