HoneyMyte, also tracked as Mustang Panda, has deployed a new 2025–2026 variant of its CoolClient backdoor that adds a signed Windows kernel-mode driver, msagent.sys, to deepen stealth and persistence during espionage intrusions. Researchers said the malware retains its multi-stage DLL sideloading design but now uses rootkit functions to hide and protect malicious processes, files, and registry objects, while also filtering network information linked to command-and-control infrastructure through an Nsiproxy hook.
In one intrusion targeting Myanmar, the group reportedly used PlugX as an initial implant before installing CoolClient from a fake Windows Defender directory via a renamed legitimate Sangfor executable. The malware persists through AutoRun entries, scheduled tasks, and Windows services, injects into synchost.exe, and can relaunch itself with elevated privileges using an RPC-based UAC bypass with PPID spoofing. Victims were identified in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, indicating HoneyMyte is expanding kernel-level defense evasion in post-compromise operations.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Kaspersky reported that HoneyMyte used the updated CoolClient in 2026 against government and private-sector organizations in India, expanding the known set of affected countries beyond Myanmar, Mongolia, Pakistan, and Russia. The activity involved the same upgraded malware family with the msagent.sys kernel driver.
A new CoolClient variant attributed to HoneyMyte/Mustang Panda was observed in late 2025 and 2026. The updated malware adds a signed kernel-mode driver, msagent.sys, to provide rootkit capabilities such as hiding malware processes, files, registry objects, and filtering network information tied to command-and-control infrastructure.
The report identified victims of the upgraded CoolClient activity in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities. The updated variant and its driver were specifically observed in intrusions in Pakistan, Mongolia, and Myanmar.
When administrative privileges were available, CoolClient extracted an embedded compressed driver, wrote it to disk as msagent.sys, and created and started a driver service named msagent. The user-mode backdoor then opened \\.\msagent and initialized the driver with IOCTL requests to trust the malware process, register protected paths, and pass the configured C2 IPv4 address.
The updated variant checked for administrator privileges and used an RPC-based UAC bypass with PPID spoofing, involving winver.exe and computerdefaults.exe, to relaunch itself with elevated rights. It then injected decrypted payload stages into suspended synchost.exe processes instead of the older write.exe target.
During execution, CoolClient established persistence through an AutoRun entry named goopdate, a scheduled task masquerading as Microsoft Windows Defender Advanced Threat Protection Service, and installation as a Windows service such as media_updaten. These mechanisms launched the malware at logon or startup and, in some cases, as SYSTEM.
In an observed campaign targeting Myanmar, HoneyMyte used PlugX as the initial post-compromise implant before deploying CoolClient. The actor prepared a fake Windows Defender directory, added Defender exclusions, and used a renamed legitimate Sangfor executable for DLL sideloading.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
12 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcecryptika.com
Open sourcesecurityaffairs.com
Open sourcesecurelist.com
Open sourcesecurelist.ru
Open sourcede.securelist.com
Open sourcede.securelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.