APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Executive Summary

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.


Intelligence Metadata - Source Publisher: Securelist - Published Date: 2026-08-14T09:00:14+00:00 - Category: malware

"Fate is in your hands and no one elses"

— Byron Pulsifer
Source: Securelist