HoneyMyte CoolClient Hides Inside a Signed Driver

Kaspersky says HoneyMyte’s CoolClient backdoor has a new Windows variant that loads a signed kernel-mode rootkit driver to hide its activity. The group, also tracked as Mustang Panda, has used CoolClient in espionage campaigns across Asia and Russia, and this latest version was observed in intrusions in Pakistan, Mongolia, and Myanmar. The malware starts a real signed driver as a Windows service, then sends it control requests so the driver can suppress what the operating system shows. That lets it conceal the CoolClient process and related files and registry entries, while also preventing those objects from being inspected or modified, so normal user-mode endpoint tools can miss the implant even when it is active. For Windows defenders, the shift matters because the hiding now sits below the layer most triage tools trust. If your visibility depends on user-mode views of processes, files, registry data, or network connections, a signed kernel driver can remove the evidence those tools would normally use to confirm compromise.

Part of the PlainSec briefing for 2026-08-14

Editions

Sources