CoolClient is a Windows backdoor family associated with the China-linked HoneyMyte threat actor, also known as Mustang Panda and Earth Preta, and used in long-running cyber-espionage operations. It has been observed as a secondary implant following PlugX infections and has targeted government and private-sector organizations across Asia and Russia, including confirmed government victims in Myanmar, Mongolia, Pakistan, and Russia.
CoolClient supports typical espionage backdoor functions including keylogging, clipboard theft, credential harvesting, file upload and download, file deletion, system reconnaissance, and plugin-based extensibility. Reporting also describes packet tunneling and collection of port-mapping information. Recent variants use a multi-stage execution chain built around DLL sideloading through a renamed legitimate Sangfor executable, staged loaders, process injection into a masquerading process, and multiple persistence mechanisms including scheduled tasks, Run-key persistence, and Windows services.
A major evolution of the family is the addition of a signed Windows kernel-mode component that gives CoolClient rootkit capabilities. This driver can hide or protect malware-related processes, files, directories, and registry objects, restrict access to protected processes, and filter network information to conceal command-and-control artifacts from user-mode tools. Analyses of the driver also identified broader latent capabilities such as shellcode injection, kernel module hiding, arbitrary kernel memory modification, and removal of certain process protections, although not all of these functions were observed in routine execution.
CoolClient is primarily a post-compromise espionage implant rather than an initial-access tool. In observed intrusions, HoneyMyte used PlugX first and then deployed CoolClient through DLL sideloading and privilege-escalation logic, including UAC-bypass techniques when administrative rights were needed to install the kernel driver. The family reflects Mustang Panda’s broader shift toward deeper stealth, stronger persistence, and more resilient post-exploitation tooling on Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A critical pre-authentication remote code execution vulnerability, CVE-2025-15467 (CVSS 9.8), affects OpenSSL versions 3.0, 3.3, 3.4, 3.5, and 3.6.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The disclosure comes as the China-linked Mustang Panda actor has been observed using an updated version of a known backdoor called COOLCLIENT that can deploy a signed kernel-mode driver ("Msagent.sys").
This includes an unreported cluster dubbed SteppeDriver that was first discovered in 2024 and has since targeted entities in France, Mongolia, and South America using tools like ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Для закрепления в системе атакующие создавали задачу планировщика, которая запускала defender.exe с правами SYSTEM при каждом старте Windows.
The latter handles persistence, registry modifications... The rootkit loads its stealth configuration from \REGISTRY\MACHINE\SYSTEM\RNG and uses separate configuration entries for directories, files, registry keys and values, and processes that should be hidden, protected, or ignored.
Для закрепления в системе атакующие создавали задачу планировщика, которая запускала defender.exe с правами SYSTEM при каждом старте Windows.
Остальные, среди прочего, поддерживают скрытие процессов и модулей ядра, внедрение шелл-кода, снятие защиты PPL и запись по произвольному адресу в памяти ядра.
It also implements a remote procedure call (RPC)-based process creation technique combined with parent process ID (PPID) spoofing to relaunch itself in an elevated context before injecting into a process named synchost.exe.
The driver enhances the malware's stealth by hiding the COOLCLIENT process, protecting related files and registry entries, and preventing them from being inspected or modified
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading... before injecting into a process named synchost.exe.
Création d’un faux dossier Windows Defender ... une application légitime Sangfor renommée en defender.exe ... processus nommé synchost.exe
Остальные, среди прочего, поддерживают скрытие процессов и модулей ядра, внедрение шелл-кода, снятие защиты PPL и запись по произвольному адресу в памяти ядра.
Files get similar treatment through a Windows filesystem minifilter. The driver maintains protected path lists and checks filesystem activity against them, denying access to matching files and directories.
It also implements a remote procedure call (RPC)-based process creation technique combined with parent process ID (PPID) spoofing to relaunch itself in an elevated context before injecting into a process named synchost.exe.
The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests. The driver enhances the malware’s stealth by hiding the CoolClient process, protecting related files and registry entries, and preventing them from being inspected or modified.
The latter handles persistence, registry modifications... The rootkit loads its stealth configuration from \REGISTRY\MACHINE\SYSTEM\RNG and uses separate configuration entries for directories, files, registry keys and values, and processes that should be hidden, protected, or ignored.
Kaspersky documented another evolution in 2025, when the malware gained clipboard theft and HTTP traffic interception for credential harvesting.
Kaspersky documented another evolution in 2025, when the malware gained clipboard theft and HTTP traffic interception for credential harvesting.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A known backdoor, first detected in 2022, associated here with Mustang Panda. The updated variant can deploy a signed kernel-mode driver to improve stealth by hiding the process and protecting files and registry entries; it also supports keylogging, clipboard theft, credential harvesting, file management, reconnaissance, and plugin-based extensions.
Backdoor used by HoneyMyte in espionage campaigns. It can log keystrokes, capture clipboard contents, steal credentials, manipulate files, collect system information, and be extended via plugins. The updated version uses a signed Windows kernel-mode driver (msagent.sys) to hide and protect processes, files, and registry objects, filter network data, and effectively add rootkit capabilities.
Backdoor/implant used by HoneyMyte, updated with a signed kernel-mode rootkit component to hide processes, files, registry keys, and C2 traffic, while protecting the CoolClient process from termination or code injection.
A backdoor/espionage implant used by Mustang Panda that supports keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, plugin-based extensibility, persistence, UAC bypass, process injection, and now kernel-level stealth via a signed driver that hides and protects processes, files, registry entries, and selected network information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.