Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
- Source: The Hacker News
- Date: 2026-08-14
- Reliability: Tier 2/4 โ Established cyber journalism
- Entity: Mustang Panda (HoneyMyte)
Summary
Mustang Panda (aka HoneyMyte) has deployed an updated CoolClient backdoor that now drops a signed Windows kernel-mode rootkit to achieve stealth. Victims observed in Myanmar, Mongolia, Pakistan and Russia, including government entities. The rootkit stage followed deployment of PlugX. Analysis was performed by Kaspersky, which published Indicators of Compromise (IoCs).
Key Facts
- CoolClient backdoor updated with a signed Windows kernel-mode rootkit
- Rootkit provides kernel-level stealth/persistence
- Victims in Myanmar, Mongolia, Pakistan and Russia, including government entities
- Deployed following PlugX in the infection chain
- Kaspersky analysis published with IoCs
Sector
Defence โ Espionage-focused APT activity against government entities across multiple states.
Source
https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html
Reliability
Tier 2 โ Established cyber journalism; based on Kaspersky's technical analysis.
Date
2026-08-14
Related Pages
No direct cross-links in this digest; related to Chinese-state-aligned espionage operations.
Sources: raw/digests/Cyber-Digest-2026-08-15