Malware/Ransomware
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Cyber RTAugust 16, 20263 min read

The HoneyMyte threat actor, also known as Mustang Panda, has deployed an updated CoolClient backdoor with a signed Windows kernel-mode rootkit, enhancing its stealth capabilities. Kaspersky identified victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The malware, following a PlugX infection, installs a driver as a Windows service, supporting keylogging and credential theft. Kaspersky shared indicators of compromise, including file hashes and C2 domains.
The HoneyMyte threat actor, also known as Mustang Panda, has been deploying an updated version of the CoolClient backdoor, which includes a signed Windows kernel-mode rootkit. This rootkit is capable of concealing and safeguarding malicious processes, files, registry objects, and command-and-control (C2) network information. Kaspersky, a Russian cybersecurity firm, has identified victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities, where CoolClient is used as a secondary backdoor following an initial PlugX infection.
The kernel component of CoolClient is deployed when the malware gains full access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege. If these conditions are unmet, the malware bypasses driver deployment and moves directly to the final-stage implant. Kaspersky has shared file hashes, paths, and C2 domains as indicators of compromise (IoCs) to aid in detection and prevention efforts.
Kaspersky's analysis confirms that the malware is a new variant of CoolClient linked to the HoneyMyte group. While the execution flow remains consistent with previous CoolClient versions, this sample introduces a new kernel-mode driver that enhances the malware's stealth capabilities significantly. The latest CoolClient variant can install the driver as a Windows service and manage it from the user-mode backdoor using input/output control (IOCTL) requests.
CoolClient is equipped with functionalities such as keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance, with additional capabilities delivered through plugins. In a campaign targeting Myanmar, HoneyMyte used PlugX as the initial implant to deploy CoolClient, creating Microsoft Defender exclusions for a fake installation directory and a renamed sideloading executable to maintain persistence.
The execution process involves the legitimate Sangfor application loading a malicious libngs.dll, which decrypts and executes the second-stage component loadcert.ini. This component manages persistence, registry modifications, User Account Control (UAC) bypass, process injection, driver deployment, and loading the final-stage cert.ini implant for C2 communications and backdoor functionality. The malware creates an AutoRun registry entry and can install a Windows service, using a remote procedure call (RPC)-based process creation technique with parent process ID (PPID) spoofing to elevate its context.
When required privileges are available, loadcert.ini extracts an embedded kernel driver, writes it as msagent.sys, and starts a driver service named msagent. This driver is digitally signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd., and Kaspersky identified older malicious drivers signed with the same certificate, though no direct connection to CoolClient activity was found. The driver receives configuration from the CoolClient user-mode component via IOCTL requests, which register trusted processes, pass C2 addresses, and protect filesystem and registry paths.
The rootkit uses a stealth configuration to hide and protect directories, files, registry keys, and processes. It registers callbacks for filesystem, registry, process, object, and image-load activities, reducing access rights to protected processes and unlinking entries from the Windows active process list. Additionally, it employs a filesystem minifilter to deny access to protected files and directories and filters C2 IPv4 addresses from network information. Kaspersky found that msagent.sys implements 33 IOCTL handlers, but only three were used in the analyzed sample.
The development of this CoolClient variant follows Kaspersky's earlier disclosure of a newer variant used in campaigns targeting Pakistan and Myanmar, which included a previously unseen rootkit. In December 2025, Kaspersky documented a different HoneyMyte kernel-mode rootkit used to load the ToneShell backdoor. The design of the new CoolClient driver is similar to the kernel-mode enhancements seen with ToneShell, with dedicated IOCTL handlers for communication with the user-mode backdoor.


