Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-15 ยท updated: 2026-08-15 ยท tags: [incident, apt, espionage, windows-rootkit, mustang-panda, backdoor, sector-defence] ยท confidence: high ยท affected_sectors: [defence] ยท au_impact: false

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

  • Source: The Hacker News
  • Date: 2026-08-14
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Entity: Mustang Panda (HoneyMyte)

Summary

Mustang Panda (aka HoneyMyte) has deployed an updated CoolClient backdoor that now drops a signed Windows kernel-mode rootkit to achieve stealth. Victims observed in Myanmar, Mongolia, Pakistan and Russia, including government entities. The rootkit stage followed deployment of PlugX. Analysis was performed by Kaspersky, which published Indicators of Compromise (IoCs).

Key Facts

  • CoolClient backdoor updated with a signed Windows kernel-mode rootkit
  • Rootkit provides kernel-level stealth/persistence
  • Victims in Myanmar, Mongolia, Pakistan and Russia, including government entities
  • Deployed following PlugX in the infection chain
  • Kaspersky analysis published with IoCs

Sector

Defence โ€” Espionage-focused APT activity against government entities across multiple states.

Source

https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html

Reliability

Tier 2 โ€” Established cyber journalism; based on Kaspersky's technical analysis.

Date

2026-08-14

Related Pages

No direct cross-links in this digest; related to Chinese-state-aligned espionage operations.

Sources: raw/digests/Cyber-Digest-2026-08-15