ZeroHour
Kaspersky Securelistpublished ()ingested Fareed Radzi

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

mediumThreat actor exploited in the wildimportance 55
AI summary · glm-5.3-flash

Kaspersky reports APT group HoneyMyte upgraded its CoolClient backdoor with a kernel-mode Windows rootkit hiding processes, files, and network connections.

Kaspersky researchers discovered a new variant of the HoneyMyte CoolClient backdoor equipped with a kernel-mode Windows rootkit driver. The rootkit hides malicious processes, files, and network connections from security tools and threat analysts, significantly increasing the backdoor's stealth. The report documents an upgrade to the APT group's backdoor tooling with a kernel-level implant.

  • New CoolClient variant ships a kernel-mode driver hiding processes, files, and network connections.
  • The rootkit conceals activity from security tools and threat analysts, aiding espionage operations.
  • Kaspersky attributes the upgraded tooling to APT group HoneyMyte.
VendorsKaspersky
Threat actorsHoneyMyte
MalwareCoolClient
OrganizationsKaspersky
Full article

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

This source does not provide full text. Read it at securelist.com.