Threats & Adversaries · APT / Espionage

HoneyMyte Adds a Signed Driver to CoolClient

Kaspersky says HoneyMyte, also tracked as Mustang Panda, has added a previously undocumented signed Windows kernel-mode driver to CoolClient, and the new variant is now showing up in intrusions across Pakistan, Mongolia, Myanmar, and other parts of Asia and Russia. The driver is loaded as a Windows service and controlled from the backdoor with IOCTLs, or input/output control commands.

That matters because the kernel driver can hide the CoolClient process, related files, registry entries, and even network clues from the tools defenders normally trust. In plain terms, the implant asks Windows to lie about what is there, so user-mode inspection can come back looking clean while the backdoor is still active.

For Windows teams handling government or diplomatic environments, the exposure sits below normal endpoint visibility. If your triage depends on process, file, registry, or network views from the user side of the machine, this version can remove the evidence those checks would normally use to confirm compromise.

2 sources · Aug 14

Timeline

Sources

Part of the PlainSec briefing for 2026-08-15

Every edition of this story: HoneyMyte Adds a Signed Driver to CoolClient

More from today