Kaspersky reported that the China-aligned espionage group Mustang Panda (aka HoneyMyte / Bronze President) has updated its CoolClient backdoor, adding capabilities to steal browser login data and monitor the clipboard, alongside broader enhancements to its data theft and reconnaissance tooling. The activity has primarily targeted government entities, with observed campaigns affecting Myanmar, Mongolia, Malaysia, and Russia (with additional reporting noting targeting in Pakistan), and CoolClient often appearing as a secondary backdoor alongside PlugX and LuminousMoth.
The updated intrusion chain commonly relies on DLL sideloading using legitimate signed executables to load malicious DLLs, with CoolClient delivered via encrypted loader components and multi-stage execution using encrypted .DAT files (e.g., main.dat). Reported functionality includes host and user profiling, file operations, keylogging, TCP tunneling, reverse-proxying, and in-memory execution of fetched plugins, with persistence achieved through Registry modifications, creation of Windows services, and scheduled tasks, plus support for UAC bypass and privilege escalation. Kaspersky also noted CoolClient being deployed via legitimate software associated with Sangfor and stated the malware has been used to deploy a previously unseen rootkit, with further technical details expected in follow-on reporting.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Kaspersky publicly reported that HoneyMyte/Mustang Panda had resurfaced with an evolved 2025 toolset centered on an upgraded CoolClient backdoor, browser credential stealers, and broader real-time surveillance and data theft capabilities.
In 2025 operations, Mustang Panda used batch and PowerShell scripts for system enumeration, internal scanning, document collection, compression, and exfiltration via FTP and public services such as Pixeldrain, with at least one case involving Firefox cookie theft to Google Drive.
Also in 2025, the actor broadened its espionage model by deploying multiple browser login-data stealers targeting Chrome, Edge, and other Chromium-based browsers, using DPAPI to decrypt saved credentials from infected systems.
In 2025, Mustang Panda enhanced CoolClient with capabilities including clipboard monitoring, active window title tracking, HTTP proxy credential sniffing, TCP/UDP command-and-control support, and in-memory plugins for file, service, and shell operations.
A 2024–2025 campaign targeting Pakistan and Myanmar delivered a CoolClient variant that also dropped a previously unseen rootkit, marking a stealth and persistence escalation.
In 2024–2025 activity, the group used DLL sideloading and trojanized legitimate software, especially Sangfor applications, to deploy newer CoolClient variants and establish persistence through services, scheduled tasks, and registry changes.
During 2024 and 2025, Mustang Panda intensified espionage activity targeting government, diplomatic, and critical infrastructure organizations across Asia and Eastern Europe, including victims in Myanmar, Mongolia, Malaysia, Russia, and Pakistan.
CoolClient has been associated with Mustang Panda since 2022, where it was used as a secondary backdoor alongside other implants such as PlugX and LuminousMoth.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcerescana.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.