CyberSecurityBoardThreat Intel · CVEs · Products

Tag: rootkit

Malware

CoolClient Backdoor Analysis

CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The…

backdoor C2 CoolClient Mustang Panda
August 14, 2026
Malware

msagent.sys Rootkit Driver

msagent.sys is a signed Windows kernel-mode driver used by the latest CoolClient variant. It provides stealth by hiding processes, files, registry keys,…

IOCTL Kernel Driver msagent.sys rootkit
August 14, 2026
Malware

FudModule Rootkit: Version 3.1 Enhancements

FudModule is a kernel-mode rootkit used by Lazarus Group since at least 2022. Version 3.1 adds the ability to disable Windows Smart…

FudModule Lazarus Group ML-KEM rootkit
August 12, 2026
Malware

iLOBleed: Rootkit Targeting HPE iLO Servers

iLOBleed is a rootkit that has been deployed on HPE iLO servers since at least 2020. It targets the Integrated Lights-Out management…

HPE iLO iLOBleed persistent malware rootkit
July 28, 2026
Malware

ToneShell Backdoor

ToneShell is a backdoor used by Mustang Panda, previously associated with a kernel-mode rootkit disclosed in December 2025. It is used for…

backdoor Mustang Panda rootkit Toneshell
June 29, 2026
Malware

MYRA: Linux Remote Access Trojan

MYRA is a full-featured Linux RAT delivered via a malicious npm package 'apintergrationpost', claiming to be a Node.js integration client for red…

fileless execution Linux MYRA npm
June 25, 2026