
HoneyMyte, also known as Mustang Panda or Bronze President, has upgraded its CoolClient backdoor with a Windows kernel-mode rootkit that can hide malicious processes, files, registry objects, kernel modules and command-and-control activity, according to new research from Kaspersky.
Kaspersky documented the activity in research published on January 27, 2026, describing changes to CoolClient and the wider toolset used by the group in campaigns across Asia and Europe.
The company said HoneyMyte’s primary targets have been government entities, with Southeast Asia particularly affected. Kaspersky’s analysis of the updated CoolClient campaign also identified browser credential stealers and scripts used for data collection and exfiltration.
CoolClient has been associated with HoneyMyte since it was publicly identified by Sophos in 2022. Trend Micro documented an updated version in 2023.
Kaspersky said later activity involving the backdoor was observed in Myanmar, Mongolia, Malaysia and Russia, with Pakistan also included in the newer activity described in its January research.
The updated CoolClient was used as a secondary backdoor alongside other HoneyMyte tools, including PlugX and LuminousMoth. Kaspersky said that, during investigations in Pakistan and Myanmar, it observed a newer CoolClient variant that dropped and executed a previously unseen rootkit. The company said a separate technical report on that rootkit would follow.
The January research also showed that CoolClient had expanded considerably from earlier versions. Kaspersky said the backdoor could collect system and user information, upload and delete files, log keystrokes, establish TCP tunnels, listen for reverse-proxy connections and load additional modules into memory.
Newer versions added clipboard monitoring, active-window tracking and the ability to capture HTTP proxy credentials.
The company also documented several HoneyMyte tools and scripts used to collect browser credentials, documents and other information after access had been obtained.
One browser credential stealer identified by Kaspersky targeted Chrome, while another targeted Microsoft Edge. A third variant could target Chromium-based browsers and was delivered through DLL side-loading.
Kaspersky assessed with high confidence that the credential stealer was used by HoneyMyte and noted code similarities with a LuminousMoth cookie stealer.
The research described activity in Myanmar, Malaysia and Thailand involving the credential stealers, with government organizations among the targets. In one incident, a Chrome credential stealer was executed first, followed minutes later by an Edge-focused variant downloaded from a remote server.
Kaspersky also identified multiple scripts used for reconnaissance and data theft. These included a batch file for system enumeration and data exfiltration, a PowerShell script for collecting and exfiltrating information, and another script designed to collect saved login data.
The group has also used legitimate signed software in its operations. According to Kaspersky, HoneyMyte abused signed software from BitDefender, VLC Media Player, Ulead PhotoImpact and several Sangfor products for DLL side-loading between 2021 and 2025.
The January report said the updated CoolClient had been deployed after other HoneyMyte malware was already present on compromised systems. BleepingComputer, in its coverage of Kaspersky’s findings, likewise reported that the previously unseen rootkit had been observed in attacks involving CoolClient and that Kaspersky planned a later technical analysis.
Kaspersky had already documented HoneyMyte’s use of a kernel-mode rootkit in a separate campaign before the CoolClient findings were published.
In its December 29, 2025 report, the company described a malicious driver used to deliver and protect a ToneShell backdoor. The campaign involved systems in Asia and was linked with government-focused cyberespionage activity.
That earlier driver was named ProjectConfiguration.sys and was registered under the same name as a Windows service. Kaspersky said it was signed with an old digital certificate issued to Guangzhou Kingteller Technology Co., Ltd. and that the certificate had been valid from 2012 to 2015. The researchers also found other malicious files carrying the same certificate but said those files were not connected to the activity described in that report.
The ToneShell campaign used the kernel driver to inject the backdoor into system processes and protect malicious files, processes and registry keys. Kaspersky said the driver used Windows kernel mechanisms, including process callbacks and filesystem filtering, to protect components of the intrusion.
The final ToneShell payload communicated with command-and-control servers and supported functions including file transfers and a remote shell.
Kaspersky assessed with high confidence that the December 2025 activity was linked to HoneyMyte because of the use of ToneShell and other tools associated with the group, including PlugX and the ToneDisk USB worm.
The company said the initial access vector remained unclear, although previously compromised machines appeared to have been used to deploy the malicious driver.
The December research provides verified evidence that HoneyMyte had already adopted kernel-mode techniques before the January 2026 CoolClient investigation. However, Kaspersky’s January publication did not provide the detailed technical analysis of the CoolClient-related rootkit contained in some later descriptions of the activity. It specifically stated that a separate report would cover the previously unseen rootkit.
As a result, claims about a CoolClient kernel driver named msagent.sys, a service called msagent, exactly 33 IOCTL handlers, specific registry locations, particular kernel structures, certificate details, hashes and command-and-control domains cannot be independently confirmed from the Kaspersky reports currently available.
Those details should therefore not be presented as established Kaspersky findings without the underlying technical report or another reputable source that independently documents them. The verified findings support a narrower conclusion: HoneyMyte has continued to develop CoolClient, expanded its information-stealing and post-exploitation capabilities, and was observed using the updated backdoor in activity where a previously unseen rootkit was also deployed.
The group’s broader toolset shows a continuing emphasis on government targets and on using multiple components after an initial compromise. Kaspersky’s research describes CoolClient alongside PlugX, LuminousMoth, ToneShell and other tools, while the group’s activity has been observed across several countries in Asia and Europe.
For defenders, the January Kaspersky report provides technical information and indicators relating to the updated CoolClient activity, while the company’s December 2025 analysis of HoneyMyte’s kernel-mode rootkit provides additional information about the group’s use of kernel-level malware in a separate ToneShell campaign.
Together, the reports show that HoneyMyte has continued to modify its malware and supporting tools while maintaining a focus on espionage operations against government organizations.
The exact technical capabilities of the previously unseen CoolClient-associated rootkit, however, remain dependent on the separate technical analysis Kaspersky said it would publish.
Sources: Kaspersky’s January 2026 CoolClient research; Kaspersky’s December 2025 HoneyMyte rootkit research; BleepingComputer’s coverage of the CoolClient campaign.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

