The HoneyMyte cyber espionage group, also known as Mustang Panda or Bronze President, has enhanced its CoolClient backdoor with a kernel-level rootkit, significantly increasing its stealth capabilities. This advancement complicates detection efforts, allowing the group to maintain prolonged access to compromised systems.
Operating primarily in regions such as Pakistan, Mongolia, Myanmar, and Russia, HoneyMyte has targeted various organizations, including government entities. In Myanmar, the group initially deployed the PlugX malware before introducing CoolClient as a secondary backdoor, indicating a strategic layering of tools to ensure persistent access.
Security researchers observed this new variant of CoolClient during investigations conducted in late 2025 and 2026. The rootkit component enables the malware to conceal processes, files, registry entries, and specific command-and-control (C2) communications, effectively evading standard security measures. By operating at the kernel level, the rootkit can manipulate system operations below the threshold of typical monitoring tools.
CoolClient’s functionalities include keystroke logging, clipboard data theft, credential harvesting, system reconnaissance, and file manipulation. The integration of the rootkit allows these operations to proceed undetected, facilitating extensive intelligence gathering and lateral movement within the victim’s network.
Infection Chain and Persistence Mechanisms
The infection process begins with the establishment of a foothold using PlugX. Subsequently, the attackers create a counterfeit Windows Defender directory, configure exclusions for this folder, and rename a legitimate Sangfor application to ‘defender.exe’ to load a malicious ‘libngs.dll’ file through DLL sideloading. This technique leverages trusted applications to execute malicious code, a method previously associated with Mustang Panda campaigns.
To ensure persistence, CoolClient sets up a scheduled task that launches the renamed application with SYSTEM privileges upon startup. Additionally, it creates an AutoRun entry and, in certain instances, a service named ‘media_updaten’. The malware injects its code into a process named ‘synchost.exe’, a deliberate misspelling designed to resemble legitimate Windows processes and evade cursory inspections.
With administrative rights, CoolClient decrypts and installs its driver as ‘msagent.sys’, registering it as a Windows driver service. Although the driver is digitally signed, the certificate, issued to Nanjing Ranyi Technology Co., Ltd., had expired years prior to the observed campaign, indicating potential misuse of outdated credentials.
Rootkit Capabilities and Concealment Techniques
The rootkit component of CoolClient employs various Windows callbacks to monitor and manipulate processes, loaded modules, files, and registry activities. It can restrict other programs’ access to the protected CoolClient process, preventing termination, inspection, or code injection attempts, thereby maintaining the backdoor’s functionality even when identified.
Furthermore, the rootkit’s file-system filter driver conceals specific folders and files by denying access during standard operations. A registry callback removes protected keys and values from enumeration results and blocks attempts to open, modify, or delete them. Additionally, the rootkit can unlink a process from Windows’ active process listings, rendering it invisible in basic task lists.
To obscure C2 communications, the rootkit hooks into the Windows Nsiproxy driver, removing registered C2 IP addresses from network data returned to user-mode tools. This manipulation ensures that defenders monitoring network connections may overlook the backdoor’s communications.
HoneyMyte’s continuous enhancement of its malware arsenal, particularly with the integration of kernel-level rootkits, underscores the evolving sophistication of cyber threats. Organizations, especially those in targeted regions and sectors, must adopt advanced detection and response strategies to counteract such stealthy and persistent threats.