Kaspersky Global Research and Analysis Team (GReAT) has identified an updated version of the CoolClient backdoor being used in a 2026 cyber-espionage campaign targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India, and Russia.

The malware has been linked to HoneyMyte, also known as Mustang Panda, and provides attackers with remote access to compromised Windows systems.

According to Kaspersky, the latest CoolClient variant represents a significant evolution of the malware, as it uses a signed kernel driver to operate deep within Windows systems and make detection and removal more difficult.

In the observed campaign, attackers used PlugX, another backdoor commonly deployed following an initial compromise, to deliver CoolClient components to targeted systems.

The attackers also configured Microsoft Defender to exclude a specific folder and file from scanning. A fake Windows Defender directory was created, and CoolClient files were placed inside it, while a legitimate Sangfor program was renamed “defender.exe” to help load malicious code.

The attackers subsequently created a scheduled task to automatically launch the renamed executable at system startup with the highest local Windows privileges.

Kaspersky Security Researcher Fareed Radzi said the new CoolClient variant can hide and protect processes, files, and registry objects while also filtering selected network information.

He said the kernel-mode driver extends the malware’s capabilities beyond earlier versions, allowing it to remain active on compromised systems while masking important traces and restricting defenders’ ability to inspect or remove it.

Kaspersky GReAT has advised organizations to remain vigilant against HoneyMyte indicators of compromise and related tools identified in the campaign.

The company recommended strengthening real-time protection, threat visibility, investigation and response capabilities, while also using threat intelligence to identify risks at an early stage.

Organizations lacking in-house cybersecurity expertise were advised to consider managed security services covering threat identification, detection, response and remediation.

Get the latest tech news, telecom insights, and product launches wherever you prefer.

Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.

Shares