CyberSecurityBoardThreat Intel · CVEs · Products
Malware

CoolClient Backdoor Analysis

August 14, 2026

CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The latest variant includes a signed kernel-mode rootkit (msagent.sys) that hides malicious activities and protects C2 communications. It is often deployed as a secondary payload after PlugX infection.