INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor
| 2026-08-14 13:08 CRITICAL HIGHExecutive Summary AI-generated
The threat actor known as HoneyMyte, operating under the guise of Mustang Panda, has been linked to a sophisticated malware campaign targeting Myanmar and other countries. The CoolClient backdoor, deployed via PlugX infections, is consistently used as a secondary post-compromise implant to deploy additional components, including Microsoft Defender exclusions and fake Windows Defender installations. This latest variant, with its digitally signed driver issued by Nanjing Ranyi Technology Co., Ltd., enables stealthy installation on Windows services and user-mode backdoors through input/output control requests. The malware's capabilities include keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and additional functionality delivered via plugins.
Technical Mitigations AI-generated
I can provide the technical mitigations in bullet points as requested. However, please note that I'll need to condense the information into a format suitable for your request.
Here are 3-5 technical mitigations:
* Use Windows Defender exclusions and rename legitimate executables to evade detection.
* Implement scheduled tasks with SYSTEM privileges to establish persistence through scheduled tasks.
* Monitor system startup and load processes to detect potential backdoor activity.
* Regularly update operating systems, software, and firmware to prevent exploitation of known vulnerabilities.
Please note that these mitigations are general recommendations and may not be applicable in all scenarios. It's essential to consult with security experts and conduct thorough risk assessments before implementing any mitigation measures.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Mustang PandaMustang Panda
PlugXPlugX
Target & Sectors
MN
RU
PK
MM
defensedefense
governmentgovernment
technologytechnology
mediamedia
Incident Timeline
September 2014
Threat actors used msagent.sys to target Windows.
Click on any entity below to view its context and source!
infrastructure
Windows
It registers filesystem, registry, process, object, and image-load callbacks that use these entries when handling activity on the infected Windows system.
The driver also implements process hiding by unlinking entries from the Windows active process list, uses a filesystem minifilter to deny access to protected files and directories, and registers a registry callback that removes protected keys and values from enumeration results and blocks attempts to modify or delete them.
A separate hook installed in the Windows Nsiproxy driver filters configured C2 IPv4 addresses from network information returned to user mode.
late 2025
Threat actors used Mustang Panda to target CoolClient.
December 2025
Mustang Panda used the ToneShell backdoor on CoolClient, exploiting a previously disclosed HoneyMyte kernel-mode rootkit.
Click on any entity below to view its context and source!
organisation
ToneShell
Kaspersky had separately
documented
a different HoneyMyte kernel-mode rootkit in December 2025 that was used to load the
ToneShell backdoor
.
January 2026
Threat actors used a signed Windows rootkit to add a backdoor called CoolClient to msagent.sys in libngs.dll.
Click on any entity below to view its context and source!
target_region
Myanmar
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
target_region
Pakistan
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
observable
msagent.sys
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
observable
libngs.dll
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
observable
9717f005c5fb98e08d2ad983d88f94ee
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
observable
9460E150E1981D5C165043520c5c12fe
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
observable
F518D8E5FE70D9090F6280C68A95998F
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
observable
2d7c8780e97409770a9d4f31c66c9d63
Among the indicators shared by Kaspersky are the following hashes -
2d7c8780e97409770a9d4f31c66c9d63 - msagent.sys
9460E150E1981D5C165043520c5c12fe - msagent.sys
9717f005c5fb98e08d2ad983d88f94ee - libngs.dll
F518D8E5FE70D9090F6280C68A95998F - libngs.dll
The development comes more than six months after Kaspersky disclosed that a newer CoolClient variant used in a campaign targeting Pakistan and Myanmar dropped and executed a previously unseen rootkit, as
The Hacker News reported
in January 2026.
August 2013 to September 2014
Threat actors used a signed Windows rootkit to install a backdoor on the CoolClient.
2026/08/14
HoneyMyte adds a signed Windows rootkit to the CoolClient backdoor for stealth.
Click on any entity below to view its context and source!
infrastructure
Windows
PlugX Deploys the CoolClient Components
In one campaign targeting Myanmar, Kaspersky said HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient, adding Microsoft Defender exclusions for a fake Windows Defender installation directory and a renamed sideloading executable.
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth.
The threat actor known as
HoneyMyte
(aka
Mustang Panda
) has been observed deploying an updated version of the
CoolClient
backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information.
According to Kaspersky's new analysis, the latest CoolClient variant can install the driver as a Windows service and control it from the user-mode backdoor through input/output control (IOCTL) requests.
The second-stage malware creates an AutoRun registry entry named goopdate and can install a Windows service named media_updaten.
IOCs
2d7c8780e97409770a9d4f31c66c9d63
msagent.sys
9460E150E1981D5C165043520C5C12FE
msagent.sys
9717F005C5FB98E08D2AD983D88F94EE
libngs.dll
F518D8E5FE70D9090F6280C68A95998F
libngs.dll
EB79558B037669792652A816E2C669DE
ctxmui.dll
C:\Program Files\microsoft\windows defender\
C:\Program Files\windows media player\mediares\
C:\ProgramData\symantecdir\
C:\ProgramData\virtualstore\
C:\Windows\identitycrl\production\
C:\Windows\serviceprofiles\networkservice\
C:\Users\<user>\AppData\Local\viber24.8\
C:\Users\<user>\AppData\Roaming\dsassistant\
C:\Program
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit.
The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests.
Before deploying the malware, the actor added both a folder exclusion and a file exclusion to Microsoft Defender for the fake Windows Defender installation directory and the renamed sideloader executable (
defender.exe
).
wmic
/
Node
:
localhost
/
Namespace
:
\
\
Root
\
Microsoft
\
Windows
\
Defender
Path
MSFT_MpPreference
call
Add
ExclusionPath
=
"$programfiles\Microsoft\Windows Defender
"
wmic
/
Node
:
localhost
/
Namespace
:
\
\
Root
\
Microsoft
\
Windows
\
Defender
Path
MSFT_MpPreference
call
Add
ExclusionPath
=
"$programfiles\Microsoft\Windows Defender\defender.exe"
The actor then created a fake Windows Defender installation directory, copied the CoolClient components into it, and renamed a legitimate Sangfor executable, usually named
Sang.exe
, to
defender.exe
to serve as the DLL sideloader.
xcopy
"$programfiles\Windows Defender\*"
"$programfiles\Microsoft\Windows Defender"
/
a
/
s
/
v
/
schtasks
/
create
/
sc
onstart
/
tn
"\Microsoft\Windows\Windows Defender Advanced Threat Protection Service"
/
tr
"\"$programfiles\Microsoft\Windows Defender\defender.exe\""
/
ru
"system"
/
F
When executed,
defender.exe
sideloads the malicious
libngs.dll
, initiating the CoolClient execution chain described in the following sections.
The loader resolves the required Windows APIs, reads
loadcert.ini
into memory, and decrypts it using a 0x32-byte repeating XOR keystream derived from a transformed seed value of
0xA4
.
Establishing AutoRun persistence
When executed with the
install
parameter, CoolClient creates an AutoRun entry under:
HKCU
\
Software
\
Microsoft
\
Windows
\
CurrentVersion
\
Run
The registry value, named
goopdate
, launches
Sang.exe
(or
defender.exe
, depending on the deployment) with the
work
parameter whenever the user logs on.
Service installation
When executed with the
install
parameter, CoolClient establishes an additional persistence mechanism by installing itself as a Windows service.
If the process is running, it constructs the path to
C:\Windows\System32\winver.exe
and establishes a connection to the local
ncalrpc
endpoint (
201ef99a-7fa0-444c-9399-19ba84f12a1a
).
As a result, the new
Sang.exe passuac
instance executes with an elevated context while appearing to have been spawned by the trusted Windows process instead of the original CoolClient process.
If both conditions are met, CoolClient extracts an embedded LZMA-compressed driver from
loadcert.ini
, decompresses it, and writes it to disk as
msagent.sys
in the same directory as
cert.ini
, for example:
C:\Program Files\Microsoft\Windows Defender\msagent.sys
Next, the malware checks whether a service named
msagent
already exists.
Finally,
0x2220F0
registers the CoolClient installation directory (for example,
C:\Program Files\Microsoft\Windows Defender\
) together with the service registry path (
\Registry\Machine\SYSTEM\CurrentControlSet\Services\media_updaten
).
This approach allows the driver to remain compatible across different Windows versions, where the layout of
EPROCESS
may differ.
During process hiding and restoration, the driver uses IOCTLs
0x22219C
and
0x2221A0
to unlink and relink entries in the Windows active process list, effectively hiding or restoring processes on demand.
organisation
the CoolClient Components
In
PlugX Deploys the CoolClient Components
In one campaign targeting Myanmar, Kaspersky said HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient, adding Microsoft Defender exclusions for a fake Windows Defender installation directory and a renamed sideloading executable.
organisation
Microsoft
PlugX Deploys the CoolClient Components
In one campaign targeting Myanmar, Kaspersky said HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient, adding Microsoft Defender exclusions for a fake Windows Defender installation directory and a renamed sideloading executable.
wmic
/
Node
:
localhost
/
Namespace
:
\
\
Root
\
Microsoft
\
Windows
\
Defender
Path
MSFT_MpPreference
call
Add
ExclusionPath
=
"$programfiles\Microsoft\Windows Defender
threat_actor
Mustang Panda
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth.
The threat actor known as
HoneyMyte
(aka
Mustang Panda
) has been observed deploying an updated version of the
CoolClient
backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information.
Introduction
CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia.
organisation
HoneyMyte
The threat actor known as
HoneyMyte
(aka
Mustang Panda
) has been observed deploying an updated version of the
CoolClient
backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information.
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit.
organisation
CoolClient
The threat actor known as
HoneyMyte
(aka
Mustang Panda
) has been observed deploying an updated version of the
CoolClient
backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information.
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit.
organisation
IOCTL
According to Kaspersky's new analysis, the latest CoolClient variant can install the driver as a Windows service and control it from the user-mode backdoor through input/output control (IOCTL) requests.
The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests.
organisation
AutoRun
The second-stage malware creates an AutoRun registry entry named goopdate and can install a Windows service named media_updaten.
Establishing AutoRun persistence
When executed with the
install
parameter, CoolClient creates an AutoRun entry under:
HKCU
\
Software
\
Microsoft
\
Windows
\
CurrentVersion
\
Run
The registry value, named
goopdate
, launches
Sang.exe
(or
defender.exe
, depending on the deployment) with the
work
parameter whenever the user logs on.
organisation
EB79558B037669792652A816E2C669DE
ctxmui.dll
IOCs
2d7c8780e97409770a9d4f31c66c9d63
msagent.sys
9460E150E1981D5C165043520C5C12FE
msagent.sys
9717F005C5FB98E08D2AD983D88F94EE
libngs.dll
F518D8E5FE70D9090F6280C68A95998F
libngs.dll
EB79558B037669792652A816E2C669DE
ctxmui.dll
C:\Program Files\microsoft\windows defender\
C:\Program Files\windows media player\mediares\
C:\ProgramData\symantecdir\
C:\ProgramData\virtualstore\
C:\Windows\identitycrl\production\
C:\Windows\serviceprofiles\networkservice\
C:\Users\<user>\AppData\Local\viber24.8\
C:\Users\<user>\AppData\Roaming\dsassistant\
C:\Program
organisation
APT
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit.
organisation
Microsoft Defender
Before deploying the malware, the actor added both a folder exclusion and a file exclusion to Microsoft Defender for the fake Windows Defender installation directory and the renamed sideloader executable (
defender.exe
).
organisation
DLL
"
wmic
/
Node
:
localhost
/
Namespace
:
\
\
Root
\
Microsoft
\
Windows
\
Defender
Path
MSFT_MpPreference
call
Add
ExclusionPath
=
"$programfiles\Microsoft\Windows Defender\defender.exe"
The actor then created a fake Windows Defender installation directory, copied the CoolClient components into it, and renamed a legitimate Sangfor executable, usually named
Sang.exe
, to
defender.exe
to serve as the DLL sideloader.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
organisation
XOR
The loader resolves the required Windows APIs, reads
loadcert.ini
into memory, and decrypts it using a 0x32-byte repeating XOR keystream derived from a transformed seed value of
0xA4
.
organisation
Sang.exe
Establishing AutoRun persistence
When executed with the
install
parameter, CoolClient creates an AutoRun entry under:
HKCU
\
Software
\
Microsoft
\
Windows
\
CurrentVersion
\
Run
The registry value, named
goopdate
, launches
Sang.exe
(or
defender.exe
, depending on the deployment) with the
work
parameter whenever the user logs on.
organisation
msagent.sys
Signed msagent.sys Driver Adds Kernel-Level Stealth
When the required privileges are available, loadcert.ini extracts an embedded LZMA-compressed kernel driver, writes it to disk as msagent.sys, and creates and starts a driver service named msagent.
Msagent.sys driver
Analysis of the deployed kernel-mode driver reveals an embedded PDB path:
PDB Path
E
:
\
work
\
南京实验室
\
2024
项目
\
张雪杰云南
m
\
研发
\
FTool
\
Tool
\
x64
\
Release
\
FTool
.
organisation
Kernel-Level Stealth
Signed msagent.sys Driver Adds Kernel-Level Stealth
When the required privileges are available, loadcert.ini extracts an embedded LZMA-compressed kernel driver, writes it to disk as msagent.sys, and creates and starts a driver service named msagent.
organisation
DllMain
Dummy export functions in libngs.dll invoking OutputDebugStringA and ExitProcess
The actual malicious logic is executed from DllMain (
DllEntryPoint
).
organisation
Nanjing Ranyi Technology Co., Ltd.
Kaspersky said the driver is digitally signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd.
The driver is digitally signed with a certificate issued to
"Nanjing Ranyi Technology Co., Ltd."
, with serial number
3E 62 DC 5D 8D 61 2A 26 33 E7 6B DF D6 07 19 DD
.
organisation
E7 6B DF
The driver is digitally signed with a certificate issued to
"Nanjing Ranyi Technology Co., Ltd."
, with serial number
3E 62 DC 5D 8D 61 2A 26 33 E7 6B DF D6 07 19 DD
.
data_breach
62 number 3E
The driver is digitally signed with a certificate issued to
"Nanjing Ranyi Technology Co., Ltd."
, with serial number
3E 62 DC 5D 8D 61 2A 26 33 E7 6B DF D6 07 19 DD
.
organisation
Command
Command handler
The command handler remains largely unchanged from previous CoolClient variants, with one notable difference: the malware now injects into
synchost.exe
instead of
write.exe
.
organisation
Analysis
Msagent.sys driver
Analysis of the deployed kernel-mode driver reveals an embedded PDB path:
PDB Path
E
:
\
work
\
南京实验室
\
2024
项目
\
张雪杰云南
m
\
研发
\
FTool
\
Tool
\
x64
\
Release
\
FTool
.
organisation
PDB
Msagent.sys driver
Analysis of the deployed kernel-mode driver reveals an embedded PDB path:
PDB Path
E
:
\
work
\
南京实验室
\
2024
项目
\
张雪杰云南
m
\
研发
\
FTool
\
Tool
\
x64
\
Release
\
FTool
.
organisation
PDB Path
Msagent.sys driver
Analysis of the deployed kernel-mode driver reveals an embedded PDB path:
PDB Path
E
:
\
work
\
南京实验室
\
2024
项目
\
张雪杰云南
m
\
研发
\
FTool
\
Tool
\
x64
\
Release
\
FTool
.
organisation
Kaspersky
Kaspersky has also published file hashes, paths, and C2 domains as indicators of compromise (IoCs).
organisation
ToneShell
The overall design is comparable to the kernel-mode enhancements previously observed in
ToneShell
, but the CoolClient driver exposes dedicated IOCTL handlers that allow the user-mode backdoor to communicate directly with the driver.
organisation
UAC
If the DLL is running under the original sideloaded process (for example,
Sang.exe
), it performs the initial setup, including persistence, UAC bypass, registry modifications, and process injection.
organisation
Kernel-Mode
Kernel-Mode driver deployment
The deployment routine begins by decrypting
time.ini
.
organisation
Next
Next, the malware repeats the same RPC-based process creation technique to launch
computerdefaults.exe
.
organisation
us.lenovoappstore[.]com
Files\common files\microsoft shared\office14\
C:\programdata\msdn\
cloudtroe.giize[.]com
employers.theworkpc[.]com
freeread.casacam[.]net
us.lenovoappstore[.]com
sundanish.freeddns[.]org
torinarlabs.webredirect[.]org
news.dursamjbataar[.]org
video.dursamjbataar[.]org
black-popular[.]com
whatismybestthing[.]com
organisation
Trend Micro
Since its first public disclosure by Sophos in
2022
and subsequent analysis by Trend Micro in
2023
, CoolClient has continued to evolve.
organisation
Similar
CoolClient components
Similar to previous variants, the latest CoolClient user-mode component follows a multi-stage execution chain, with each component performing a distinct role during execution.
organisation
ExitProcess
Each export simply calls
OutputDebugStringA
with its corresponding function name before immediately invoking
ExitProcess
, serving no functional purpose other than mimicking the expected export table of the legitimate DLL.
organisation
Elevated
Elevated relaunch and UAC bypass
To continue execution with elevated privileges while concealing its true parent process, CoolClient implements an RPC-based process creation technique similar to the method described by
Google Project Zero
.
organisation
RPC
Elevated relaunch and UAC bypass
To continue execution with elevated privileges while concealing its true parent process, CoolClient implements an RPC-based process creation technique similar to the method described by
Google Project Zero
.
organisation
Driver
Driver initialization
After the driver is loaded, CoolClient establishes communication with it by opening the device
\\.\msagent
using
CreateFileW
.
organisation
DeviceIoControl
The user-mode component then initializes the driver by issuing three
DeviceIoControl
requests.
organisation
WinStation
Before creating the target process, the malware enumerates active WinStation sessions to identify a suitable interactive user session.
organisation
OSINT
However, our OSINT analysis did not identify any information linking these strings to a known organization, developer, or threat actor.
organisation
ActiveProcessLinks
The driver validates candidate ActiveProcessLinks layouts before enabling process hiding
Once the correct offset has been identified, it is stored for later use by the process hiding routines.
organisation
AVL
Process, object, and image load callbacks
After preparing its process tracking structures, the driver initializes several AVL trees and populates them with configuration entries loaded from the registry, including
Wid_H1deF5Dirs, Wid_H1deF5Files, Wid_H1deRegKeys, Wid_H1deRegValues, Hid_IgnoredImages, Hid_ProtectedImages, and Hid_HideImages
.
organisation
Handler
Functionality
IOCTL
Handler
Functionality
0x222000
0x140001E04
Enable or disable the rootkit.
organisation
Register
0x2220F0
0x140002320
● Register protected filesystem or registry paths
● Used by CoolClient to register its installation directory and service registry key.
organisation
PID
0x222130
0x14000265C
Register a protected process by PID.
organisation
NtCreateThreadEx
0x222134
0x140010E88
Inject shellcode into a target process using NtCreateThreadEx.
organisation
Delete
0x222144
0x14000270C
Delete a file.
organisation
Remove Protected Process Light
0x222168
0x140002780
Unmap the image section of a target process.
0x22216C
0x140013984
Terminate a process by PID.
0x222194
0x140011F50
Remove Protected Process Light (PPL) protection.
organisation
0x14000F954
Restore
0x2221A8
0x14000F954
Restore a hidden module.
organisation
0x140016368
0x2221AC
0x140016368
Enumerate and restore kernel notification callbacks.
organisation
Enumerate
0x2221AC
0x140016368
Enumerate and restore kernel notification callbacks.
organisation
Kernel
Kernel module enumeration and hiding
To support kernel module hiding, the driver resolves the address of the non-exported kernel variable
PsLoadedModuleList
at runtime using
MmGetSystemRoutineAddress
.
organisation
Nsiproxy
Nsiproxy hooking and data filtering
The driver also hooks the Nsiproxy driver to filter network-related data returned to user mode.
organisation
\Driver\Nsiproxy
To install the hook, the driver obtains a reference to
\Driver\Nsiproxy
using
ObReferenceObjectByName
and replaces one of the Nsiproxy handler pointers with its own filtering routine.
organisation
IP
Matching IP addresses are removed before the data is returned to user mode, preventing applications that rely on Nsiproxy-provided network information from seeing the malware’s C2 addresses.
organisation
DriverUnload
Finally, the driver registers a
DriverUnload
routine to release allocated resources when the driver is unloaded.
infrastructure
1 Description
Registry configuration loaded by the driver during initialization
Two
REG_DWORD
values control the driver’s operating mode:
Registry Value
Default
Description
Hid_State
1
Enables the driver’s rootkit functionality.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
PlugX Deploys the CoolClient Components
In one campaign targeting Myanmar, Kaspersky said HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient, adding Microsoft Defender exclusions for a fake Windows Defender installation directory and a renamed sideloading executable.
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth.
The threat actor known as
HoneyMyte
(aka
Mustang Panda
) has been observed deploying an updated version of the
CoolClient
backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information.
According to Kaspersky's new analysis, the latest CoolClient variant can install the driver as a Windows service and control it from the user-mode backdoor through input/output control (IOCTL) requests.
The second-stage malware creates an AutoRun registry entry named goopdate and can install a Windows service named media_updaten.
It registers filesystem, registry, process, object, and image-load callbacks that use these entries when handling activity on the infected Windows system.
The driver also implements process hiding by unlinking entries from the Windows active process list, uses a filesystem minifilter to deny access to protected files and directories, and registers a registry callback that removes protected keys and values from enumeration results and blocks attempts to modify or delete them.
A separate hook installed in the Windows Nsiproxy driver filters configured C2 IPv4 addresses from network information returned to user mode.
IOCs
2d7c8780e97409770a9d4f31c66c9d63
msagent.sys
9460E150E1981D5C165043520C5C12FE
msagent.sys
9717F005C5FB98E08D2AD983D88F94EE
libngs.dll
F518D8E5FE70D9090F6280C68A95998F
libngs.dll
EB79558B037669792652A816E2C669DE
ctxmui.dll
C:\Program Files\microsoft\windows defender\
C:\Program Files\windows media player\mediares\
C:\ProgramData\symantecdir\
C:\ProgramData\virtualstore\
C:\Windows\identitycrl\production\
C:\Windows\serviceprofiles\networkservice\
C:\Users\<user>\AppData\Local\viber24.8\
C:\Users\<user>\AppData\Roaming\dsassistant\
C:\Program
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit.
The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests.
Before deploying the malware, the actor added both a folder exclusion and a file exclusion to Microsoft Defender for the fake Windows Defender installation directory and the renamed sideloader executable (
defender.exe
).
wmic
/
Node
:
localhost
/
Namespace
:
\
\
Root
\
Microsoft
\
Windows
\
Defender
Path
MSFT_MpPreference
call
Add
ExclusionPath
=
"$programfiles\Microsoft\Windows Defender
"
wmic
/
Node
:
localhost
/
Namespace
:
\
\
Root
\
Microsoft
\
Windows
\
Defender
Path
MSFT_MpPreference
call
Add
ExclusionPath
=
"$programfiles\Microsoft\Windows Defender\defender.exe"
The actor then created a fake Windows Defender installation directory, copied the CoolClient components into it, and renamed a legitimate Sangfor executable, usually named
Sang.exe
, to
defender.exe
to serve as the DLL sideloader.
xcopy
"$programfiles\Windows Defender\*"
"$programfiles\Microsoft\Windows Defender"
/
a
/
s
/
v
/
schtasks
/
create
/
sc
onstart
/
tn
"\Microsoft\Windows\Windows Defender Advanced Threat Protection Service"
/
tr
"\"$programfiles\Microsoft\Windows Defender\defender.exe\""
/
ru
"system"
/
F
When executed,
defender.exe
sideloads the malicious
libngs.dll
, initiating the CoolClient execution chain described in the following sections.
The loader resolves the required Windows APIs, reads
loadcert.ini
into memory, and decrypts it using a 0x32-byte repeating XOR keystream derived from a transformed seed value of
0xA4
.
Establishing AutoRun persistence
When executed with the
install
parameter, CoolClient creates an AutoRun entry under:
HKCU
\
Software
\
Microsoft
\
Windows
\
CurrentVersion
\
Run
The registry value, named
goopdate
, launches
Sang.exe
(or
defender.exe
, depending on the deployment) with the
work
parameter whenever the user logs on.
Service installation
When executed with the
install
parameter, CoolClient establishes an additional persistence mechanism by installing itself as a Windows service.
If the process is running, it constructs the path to
C:\Windows\System32\winver.exe
and establishes a connection to the local
ncalrpc
endpoint (
201ef99a-7fa0-444c-9399-19ba84f12a1a
).
As a result, the new
Sang.exe passuac
instance executes with an elevated context while appearing to have been spawned by the trusted Windows process instead of the original CoolClient process.
If both conditions are met, CoolClient extracts an embedded LZMA-compressed driver from
loadcert.ini
, decompresses it, and writes it to disk as
msagent.sys
in the same directory as
cert.ini
, for example:
C:\Program Files\Microsoft\Windows Defender\msagent.sys
Next, the malware checks whether a service named
msagent
already exists.
Finally,
0x2220F0
registers the CoolClient installation directory (for example,
C:\Program Files\Microsoft\Windows Defender\
) together with the service registry path (
\Registry\Machine\SYSTEM\CurrentControlSet\Services\media_updaten
).
This approach allows the driver to remain compatible across different Windows versions, where the layout of
EPROCESS
may differ.
During process hiding and restoration, the driver uses IOCTLs
0x22219C
and
0x2221A0
to unlink and relink entries in the Windows active process list, effectively hiding or restoring processes on demand.
Metrics
data_breach
62
Number 3E
The driver is digitally signed with a certificate issued to
"Nanjing Ranyi Technology Co., Ltd."
, with serial number
3E 62 DC 5D 8D 61 2A 26 33 E7 6B DF D6 07 19 DD
.
Metrics
infrastructure
1
Description
Registry configuration loaded by the driver during initialization
Two
REG_DWORD
values control the driver’s operating mode:
Registry Value
Default
Description
Hid_State
1
Enables the driver’s rootkit functionality.
Intelligence Sources
Kaspersky
2026-08-14
The Hacker News
2026-08-14
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-18T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
52x
organisation
Identified Entity
the CoolClient Components
In
entity
15x
timeline
Temporal Reference
January 2026
date
4x
source region
Origin Country
Russian Federation
country
4x
industry
Targeted Sector
Government
sector
4x
target region
Target Country
Myanmar
country
4x
tactic
Cyber Operation Type
Keylogging
tactic
4x
attribution
Attributing Entity
User Account Control
authority
3x
tactic
MITRE ATT&CK Technique
T1014 - Rootkit
technique
2x
general metric
E7 Df D6
61
e7 df d6
Contextual Telemetry
Context Block
9 METRICS
malware
Malware Payload
PlugX
tool
infrastructure
Affected Product
Windows
software
threat actor
APT Group
Mustang Panda
actor
general metric
Ioctl Handlers
33
ioctl handlers
data breach
Number 3E
62
number 3e
general metric
Dd
19
dd
general metric
Software Processes
360
software processes
infrastructure
Description
1
description
general metric
Controls
0
controls
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.