APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Kaspersky Securelist Version 1 original current

Imported from official source

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

This version

Version
1 of 1
Recorded
September 20, 2026 19:52
Change
Initial
Content hash
87ffb8796a74120901b7d041e5f164fa
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.