Security2 distinct publishers3 min readPublished Updated
Securelist says the newest CoolClient deploys a signed kernel-mode driver as a Windows service to hide its process, files and registry keys. It was seen in Pakistan, Mongolia and Myanmar.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Securelist reports that the newest variant of CoolClient, the backdoor family it attributes to the HoneyMyte APT group, also tracked as Mustang Panda, can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests [1][6]. According to the same analysis the driver hides the CoolClient process and protects its files and registry entries from inspection or modification [7], which puts a routine espionage toolkit underneath the layer where most endpoint agents do their looking.
This is not a novel implant getting a novel trick. CoolClient already did keylogging, clipboard theft, credential harvesting, file management, system reconnaissance and plugin-based extensions [2], against organisations across Asia and Russia [3]. It was first publicly disclosed by Sophos in 2022 and analysed by Trend Micro in 2023 [4], and Securelist says a 2025 variant added clipboard theft and HTTP traffic interception for credential harvesting [5]. The kernel component surfaced in investigations covering late 2025 and 2026 [6], roughly three to four years after the family became public [21]. Securelist also notes the overall design is comparable to kernel-mode enhancements previously seen in ToneShell, though the CoolClient driver exposes dedicated IOCTL handlers for the user-mode backdoor to talk to it directly [8]. That reads as shared engineering inside the cluster rather than a one-off experiment.
The delivery around it is unremarkable, which is the point. In the Myanmar intrusion Securelist describes, PlugX was the initial post-compromise implant used to deploy the CoolClient components [9]. Before dropping anything, the operator added a folder exclusion and a file exclusion to Microsoft Defender covering a fake Windows Defender installation directory and the renamed sideloader binary [10], created that fake directory and copied the components into it [11], then renamed a legitimate Sangfor executable, usually Sang.exe, to defender.exe to act as the DLL sideloader [12]. Persistence was a scheduled task launching defender.exe with SYSTEM privileges at startup [13], and defender.exe sideloads the malicious libngs.dll to start the chain [14].
The loader is built to waste an analyst's time and to defeat name-based rules. libngs.dll exports numerous dummy functions that each call OutputDebugStringA and then ExitProcess [15], with the real logic in DllMain behind control flow flattening and unconditional jumps [16]. It decrypts the second stage with a 0x32-byte repeating XOR keystream derived from a transformed seed value of 0xA4 [17] and loads the DLL directly in memory [18]. The second- and final-stage files, previously loader.dat and main.dat, are now loadcert.ini and cert.ini [19], and the second stage prepares the environment before moving into an injected synchost.exe [20]. Any detection keyed to the old filenames is already stale.
What to watch: the published Securelist text reviewed here does not name the certificate that signed the driver, publish its hash, or say whether this is a legitimate signed driver being abused or attacker-obtained signing [22]. That distinction decides whether a vulnerable-driver blocklist is a control or paperwork. Until it is answered, the durable telemetry is not the driver itself but its scaffolding: new kernel service creation, driver image loads on servers that have no business loading one, Defender exclusion writes, and SYSTEM scheduled tasks pointing at directories that imitate Microsoft's own [6][10][13].
Ranked by verification strength, evidence, and original report placement.
CoolClient is a backdoor family attributed to the HoneyMyte APT group, also known as Mustang Panda, used in cyber-espionage campaigns.
CoolClient supports keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions.
CoolClient has been used in campaigns targeting organizations across Asia and Russia.
CoolClient was first publicly disclosed by Sophos in 2022, with subsequent analysis by Trend Micro in 2023.
In 2025 Securelist analyzed a newer CoolClient variant that introduced clipboard theft and HTTP traffic interception for credential harvesting.
Investigations covering late 2025 and 2026 found that the newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party reverse engineering, but single vendor and no publishable indicators in the supplied text
The source provides granular, checkable technical detail (sideloaded binary names, export-table decoy behaviour, XOR keystream seeds, stage filenames, injection target, persistence mechanism) drawn from the vendor's own investigations. It is nonetheless a single publisher with no independent corroboration in this cluster, and the supplied text carries no hashes, certificate identity or IOC list, and is truncated before the driver's IOCTL handlers are documented.
Confirmed in-the-wild use in at least three countries, with no victim counts disclosed
Adoption here is real-world deployment of the tooling: the vendor states it observed the driver-equipped variant in intrusions in Pakistan, Mongolia and Myanmar, with a described end-to-end Myanmar chain from PlugX to the CoolClient components. That is more than a lab finding, but the scope stays narrow and unquantified: no victim numbers, sectors, or timeline of campaign volume are given, and only one vendor's telemetry is represented.
Slightly overstated: EDR-blinding framing runs ahead of the stated process/file/registry hiding
The underlying research is sober and artefact-rich, and the escalation from user-mode implant to kernel rootkit is genuinely material. The cluster framing nonetheless stretches it in two places: the source claims the driver hides the process and protects files and registry entries, not that it defeats EDR generally, and the load-bearing word 'signed' is presented without a certificate identity, hash, or any statement on whether a legitimate signature is being abused. Those gaps push the narrative modestly ahead of the evidence.
Vendor-authored threat research: original telemetry, but the publisher benefits from the finding
The only source is a security vendor's research blog reporting its own investigations. That yields genuine first-party visibility, and the write-up is technical rather than promotional in the supplied text, but the publisher has a standing interest in demonstrating detection reach against a named APT and no competing-interest disclosure accompanies the analysis. Nothing in the supplied material describes pricing, product placement or commercial framing, so this is scored on publisher role alone.
Moderate: internally consistent and specific, but uncorroborated and incomplete on the key signing question
The technical narrative is coherent and specific enough to act on behaviourally, and the in-the-wild observation is stated plainly. Confidence is held below high because the cluster has one publisher, the supplied body is truncated before the driver internals, and the most consequential detail, how a kernel driver came to be signed and loadable, is unresolved.
security
QUICSILVER runs its C2 over QUIC, and most port-443 inspection is scoped to TCP1 distinct publisher
security
ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL1 distinct publisher
build
PyInstaller exits zero, then the real work starts: notarization traps that report success1 distinct publisher
security
One transitive import is enough: 14 npm packages that run a Linux backdoor with no install hook1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026
1 article · August 16, 2026