Mustang Panda Deploys Signed Windows Rootkit in Updated CoolClient Backdoor
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The…
Fortinet FortiGuard Labs has disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese…
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been…
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
The China-aligned espionage group Mustang Panda is running two campaigns against Indian government and hydropower targets, deploying new malware and turning a…
Mustang Panda, also known as HoneyMyte, is a China-linked advanced persistent threat (APT) group active since at least 2013. It primarily targets…
SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…
MINIRECON is a reworked variant of the Toneshell backdoor, beaconing over WebSocket on HTTPS, used by Mustang Panda.
ZOHOMURK is a novel malware that uses hardcoded Zoho OAuth credentials to turn an attacker-controlled WorkDrive account into a dead drop for…