INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor

| 2026-08-14 13:08 CRITICAL HIGH
Executive Summary AI-generated
The threat actor known as HoneyMyte, operating under the guise of Mustang Panda, has been linked to a sophisticated malware campaign targeting Myanmar and other countries. The CoolClient backdoor, deployed via PlugX infections, is consistently used as a secondary post-compromise implant to deploy additional components, including Microsoft Defender exclusions and fake Windows Defender installations. This latest variant, with its digitally signed driver issued by Nanjing Ranyi Technology Co., Ltd., enables stealthy installation on Windows services and user-mode backdoors through input/output control requests. The malware's capabilities include keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and additional functionality delivered via plugins.
Technical Mitigations AI-generated
I can provide the technical mitigations in bullet points as requested. However, please note that I'll need to condense the information into a format suitable for your request. Here are 3-5 technical mitigations: * Use Windows Defender exclusions and rename legitimate executables to evade detection. * Implement scheduled tasks with SYSTEM privileges to establish persistence through scheduled tasks. * Monitor system startup and load processes to detect potential backdoor activity. * Regularly update operating systems, software, and firmware to prevent exploitation of known vulnerabilities. Please note that these mitigations are general recommendations and may not be applicable in all scenarios. It's essential to consult with security experts and conduct thorough risk assessments before implementing any mitigation measures.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Mustang PandaMustang Panda PlugXPlugX
Target & Sectors
MN RU PK MM
defensedefense governmentgovernment technologytechnology mediamedia
Incident Timeline
‎September 2014
Threat actors used msagent.sys to target Windows.
infrastructure Windows
‎late 2025
Threat actors used Mustang Panda to target CoolClient.
‎December 2025
Mustang Panda used the ToneShell backdoor on CoolClient, exploiting a previously disclosed HoneyMyte kernel-mode rootkit.
organisation ToneShell
‎January 2026
Threat actors used a signed Windows rootkit to add a backdoor called CoolClient to msagent.sys in libngs.dll.
target_region Myanmar
target_region Pakistan
observable msagent.sys
observable libngs.dll
observable 9717f005c5fb98e08d2ad983d88f94ee
observable 9460E150E1981D5C165043520c5c12fe
observable F518D8E5FE70D9090F6280C68A95998F
observable 2d7c8780e97409770a9d4f31c66c9d63
‎August 2013 to September 2014
Threat actors used a signed Windows rootkit to install a backdoor on the CoolClient.
‎2026/08/14
HoneyMyte adds a signed Windows rootkit to the CoolClient backdoor for stealth.
infrastructure Windows
organisation the CoolClient Components In
organisation Microsoft
threat_actor Mustang Panda
organisation HoneyMyte
organisation CoolClient
organisation IOCTL
organisation AutoRun
organisation EB79558B037669792652A816E2C669DE ctxmui.dll
organisation APT
organisation Microsoft Defender
organisation DLL
organisation XOR
organisation Sang.exe
organisation msagent.sys
organisation Kernel-Level Stealth
organisation DllMain
organisation Nanjing Ranyi Technology Co., Ltd.
organisation E7 6B DF
data_breach 62 number 3E
organisation Command
organisation Analysis
organisation PDB
organisation PDB Path
organisation Kaspersky
organisation ToneShell
organisation UAC
organisation Kernel-Mode
organisation Next
organisation us.lenovoappstore[.]com
organisation Trend Micro
organisation Similar
organisation ExitProcess
organisation Elevated
organisation RPC
organisation Driver
organisation DeviceIoControl
organisation WinStation
organisation OSINT
organisation ActiveProcessLinks
organisation AVL
organisation Handler Functionality
organisation Register
organisation PID
organisation NtCreateThreadEx
organisation Delete
organisation Remove Protected Process Light
organisation 0x14000F954 Restore
organisation 0x140016368
organisation Enumerate
organisation Kernel
organisation Nsiproxy
organisation \Driver\Nsiproxy
organisation IP
organisation DriverUnload
infrastructure 1 Description
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
62
Number 3E
Metrics
infrastructure
1
Description