APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Kaspersky documents HoneyMyte's CoolClient backdoor gaining a kernel-mode rootkit that blinds EDR tools — a significant stealth upgrade for this China-linked APT targeting government and diplomatic entities.
Summary written by editorial AI · Source link below
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Editorial Analysis
The addition of kernel-level evasion to a known APT toolkit means that organisations relying solely on userland EDR may miss active compromises, especially in sectors historically targeted by HoneyMyte.
Verify that endpoint protection includes kernel-integrity monitoring and driver-load auditing, and hunt for published CoolClient IOCs across your estate.
A state-linked APT group has added kernel-level rootkit capabilities that can evade standard endpoint security tools.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Securelist (Kaspersky) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d