Home / Aug 18, 2026 / Story
0
#8 The Hacker News general August 14, 2026 at 13:08 UTC

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

By [email protected] (The Hacker News)

AI Summary

Mustang Panda (HoneyMyte) has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit capable of hiding malicious processes, files, registry keys, and C2 network traffic, with victims identified in Myanmar, Mongolia, and Pakistan. The use of a legitimately signed rootkit significantly raises the bar for detection on affected endpoints.

Relevance score: 76.0/100

# More from August 18