HackerFeeds

CyberSecurity News

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

The Hacker News
· August 14, 2026

AI summary

Mustang Panda, also known as HoneyMyte, has updated the CoolClient backdoor with a signed Windows kernel-mode rootkit. This rootkit can conceal and protect various malicious components, including processes, files, and network communications. The addition of the rootkit is intended to enhance the stealth capabilities of the backdoor. Kaspersky, a Russian cybersecurity vendor, has identified victims of this updated backdoor in several countries, including Myanmar, Mongolia, and Pakistan. The use of a signed rootkit suggests an attempt to make the malware more difficult to detect. Victims have been found in multiple Asian countries.

Read the full article at The Hacker Newsthehackernews.com/2026/08/mustang-panda-adds-signed-windows.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.