← Back to Daily Briefing

Mustang Panda (HoneyMyte) has upgraded its CoolClient backdoor by integrating a kernel-mode rootkit signed with a digital certificate that expired in September 2014. This attack leverages a systemic flaw in Windows' driver signature enforcement, specifically the continued trust for legacy cross-signed drivers. By executing at the kernel level, the rootkit achieves high-privilege persistence and total invisibility by manipulating kernel objects to hide malicious processes, registry keys, and Command and Control (C2) network traffic. This effectively bypasses standard Endpoint Detection and Response (EDR) telemetry, posing a significant threat to Windows environments that have not transitioned away from legacy trust mechanisms.

  • Campaign Overview: Mustang Panda Operations

    • Threat Actor Profile: Mustang Panda (HoneyMyte) is utilizing an updated CoolClient backdoor variant for initial access.
    • Geographic Scope: Active targeting has been observed in Myanmar, Mongolia, and Pakistan.
    • Operational Goal: Achieving stealthy, high-privilege persistence via kernel-mode execution.
  • Technical Deep Dive: Certificate & Driver Exploitation

    • Cryptographic Failure: The rootkit is signed with a 2013-era certificate that expired in September 2014.
    • Legacy Trust Vector: The driver loads successfully because Windows still honors legacy cross-signing mechanisms.
    • Kernel Manipulation: The driver operates at the highest privilege level to alter system-level objects.
  • Systemic Impact: EDR Bypass and Invisibility

    • Process & File Masking: The rootkit hides malicious processes and files from both the OS and security tools.
    • Network Obfuscation: Malicious C2 network sockets are hidden, preventing detection via standard network telemetry.
    • Telemetry Blindness: Kernel-level interference allows the attacker to bypass or disable typical EDR/AV monitoring.
  • Defense and Remediation: Industry Response

    • Vendor Discovery: Kaspersky and Xcitium identified the specific HoneyMyte rootkit and the certificate expiration vulnerability.
    • Microsoft Mitigation: Microsoft is actively moving to deprecate and remove trust for legacy cross-signed drivers.
    • Defensive Posture: Organizations should prioritize implementing the latest driver signing policies and monitoring for unauthorized kernel-mode driver loads.

Related posts

  1. threatlabsnews.xcitium.com — A 2014 Certificate Still Loads Kernel Rootkits in 2026
  2. Kaspersky Securelist — APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
  3. feeds.feedburner.com — Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
  4. Security Affairs — Mustang Panda Upgrades CoolClient With a Kernel Rootkit
  5. gbhackers.com — HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections
  6. Magicsword
  7. Support
  8. Techcommunity
  9. Techpowerup
  10. S3-us-west-2
  11. Reddit

LINK COPIED TO CLIPBOARD