Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
An new version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that may conceal and safeguard harmful processes, files, registry objects, and command-and-control (C2) network data has been seen being used by the threat actor HoneyMyte (also known as Mustang Panda).
CoolClient was regularly used as a secondary backdoor after a PlugX infection, according to Russian cybersecurity company Kaspersky, which found victims in Myanmar, Mongolia, Pakistan, and Russia, including verified government agencies.
When CoolClient has complete access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege, the kernel component is deployed. The malware moves on to the final-stage implant and bypasses driver distribution if those requirements are not satisfied.
Add...






