The HoneyMyte (Mustang Panda) group has significantly increased the CoolClient backdoor. The new version has received a driver for the Windows kernel, which helps to hide malicious process, files, registry records and network activity. The updated CoolClient has already been applied against organizations in Russia and several Asian countries.
CoolClient has been used in spy operations since at least 2022. The backdoor is able to record keystrokes, copy the contents of the clipboard, steal credentials, manage files, and collect information about the system. In a 2025 version, the backdoor began intercepting data from the clipboard and analyzing HTTP traffic to steal credentials.
In late 2025 and 2026, Kaspersky discovered a new variant of CoolClient with a signed driver msagent.sys. The malicious program installs the driver as a Windows system service and transmits commands to it through special requests. The driver can hide processes and protect registry files and partitions so that they cannot be viewed, changed or deleted, and filtered information about network connections.
In one of the attacks on organizations in Myanmar, HoneyMyte first used PlugX and then installed CoolClient. Before running the malware, operators added malicious files to Microsoft Defender exceptions, created a fake Windows Defender directory, and placed CoolClient components there. To launch it, used the legitimate Sangfor program, renamed to defense.exe, which downloaded the malicious library.
In the system, the program was fixed through the task scheduler, autostart record and Windows service. CoolClient also tried to get increased rights and then implemented his code in the synchost.exe process. If the rights were enough, the program extracted the built-in msagent.sys driver, wrote it to the disk and launched it through a separate system service.
The driver received 33 team handlers. In the attack, CoolClient used only three of them. The first marked his own process as a trusted one, the second transmitted to the driver the IP address of the control server, the third set the files and registry records that need to be hidden or protected.
The driver's capabilities are much wider. It is able to hide processes and modules of the kernel, limit access to selected processes, delete files, change the registry, complete processes and hide the network addresses of the control infrastructure. The files protect the file system filter, and registry records are a separate handler that hides secure records from regular programs and does not allow them to be changed.
The driver was signed by Nanjing Ranyi Technology Co., Ltd., which was valid from August 2013 to September 2014. Kaspersky found other old malicious drivers with the same certificate, but the direct link between them and the current CoolClient operations was not established.
The new CoolClient was found in attacks on organizations in Myanmar, Mongolia, Pakistan and Russia, including state structures. In all the cases studied, the operators first penetrated the network using PlugX and then installed CoolClient. Due to the fact that the grouping added functions at the level of the Windows kernel, it became noticeably more difficult to detect the backdoor, and this shows that HoneyMyte continues to develop means of secretive presence in infected systems.
CoolClient has been used in spy operations since at least 2022. The backdoor is able to record keystrokes, copy the contents of the clipboard, steal credentials, manage files, and collect information about the system. In a 2025 version, the backdoor began intercepting data from the clipboard and analyzing HTTP traffic to steal credentials.
In late 2025 and 2026, Kaspersky discovered a new variant of CoolClient with a signed driver msagent.sys. The malicious program installs the driver as a Windows system service and transmits commands to it through special requests. The driver can hide processes and protect registry files and partitions so that they cannot be viewed, changed or deleted, and filtered information about network connections.
In one of the attacks on organizations in Myanmar, HoneyMyte first used PlugX and then installed CoolClient. Before running the malware, operators added malicious files to Microsoft Defender exceptions, created a fake Windows Defender directory, and placed CoolClient components there. To launch it, used the legitimate Sangfor program, renamed to defense.exe, which downloaded the malicious library.
In the system, the program was fixed through the task scheduler, autostart record and Windows service. CoolClient also tried to get increased rights and then implemented his code in the synchost.exe process. If the rights were enough, the program extracted the built-in msagent.sys driver, wrote it to the disk and launched it through a separate system service.
The driver received 33 team handlers. In the attack, CoolClient used only three of them. The first marked his own process as a trusted one, the second transmitted to the driver the IP address of the control server, the third set the files and registry records that need to be hidden or protected.
The driver's capabilities are much wider. It is able to hide processes and modules of the kernel, limit access to selected processes, delete files, change the registry, complete processes and hide the network addresses of the control infrastructure. The files protect the file system filter, and registry records are a separate handler that hides secure records from regular programs and does not allow them to be changed.
The driver was signed by Nanjing Ranyi Technology Co., Ltd., which was valid from August 2013 to September 2014. Kaspersky found other old malicious drivers with the same certificate, but the direct link between them and the current CoolClient operations was not established.
The new CoolClient was found in attacks on organizations in Myanmar, Mongolia, Pakistan and Russia, including state structures. In all the cases studied, the operators first penetrated the network using PlugX and then installed CoolClient. Due to the fact that the grouping added functions at the level of the Windows kernel, it became noticeably more difficult to detect the backdoor, and this shows that HoneyMyte continues to develop means of secretive presence in infected systems.