Mustang Panda Deploys Signed Windows Rootkit in Updated CoolClient Backdoor
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The…
msagent.sys is a signed Windows kernel-mode driver used by the latest CoolClient variant. It provides stealth by hiding processes, files, registry keys,…
FudModule is a kernel-mode rootkit used by Lazarus Group since at least 2022. Version 3.1 adds the ability to disable Windows Smart…
iLOBleed is a rootkit that has been deployed on HPE iLO servers since at least 2020. It targets the Integrated Lights-Out management…
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm,…
Daxin (srt64.sys) is a kernel-mode rootkit first documented by Symantec in March 2022, used in targeted attacks since 2013. It monitors incoming…
ToneShell is a backdoor used by Mustang Panda, previously associated with a kernel-mode rootkit disclosed in December 2025. It is used for…
MYRA is a full-featured Linux RAT delivered via a malicious npm package 'apintergrationpost', claiming to be a Node.js integration client for red…