Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit, enhancing its stealth capabilities. According to Kaspersky, the threat actor targeted government entities in Myanmar, Mongolia, Pakistan, and Russia, using CoolClient as a secondary backdoor after an initial PlugX infection.
The kernel component, named msagent.sys, is deployed when CoolClient has full access to the Service Control Manager and the SeTcbPrivilege privilege. It is installed as a Windows service and controlled via IOCTL requests from the user-mode backdoor. The rootkit can hide and protect malicious processes, files, registry objects, and C2 network information. It registers filesystem, registry, process, object, and image-load callbacks to enforce stealth configurations.
In one campaign targeting Myanmar, PlugX was used to deploy CoolClient, with Microsoft Defender exclusions added for a fake Windows Defender directory. The malware used a renamed Sangfor executable for DLL sideloading and established persistence via a scheduled task. The second-stage component loadcert.ini handles persistence, UAC bypass, process injection, and driver deployment.
The driver is signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd., valid from August 2013 to September 2014. Kaspersky identified older malicious drivers signed with the same certificate but found no direct link to CoolClient. The rootkit implements 33 IOCTL handlers, though only three were observed in normal execution: registering the CoolClient process as trusted, passing the C2 IPv4 address, and registering protected filesystem and registry paths.
Kaspersky has published file hashes, paths, and C2 domains as indicators of compromise. This development follows previous disclosures of HoneyMyte kernel-mode rootkits, including one used to load the ToneShell backdoor in December 2025.
Attack groups: Mustang Panda, HoneyMyte
Malware: CoolClient, PlugX, ToneShell, msagent.sys
Companies: Kaspersky, Nanjing Ranyi Technology Co., Ltd.
Original source: thehackernews.com