Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Kaspersky documents HoneyMyte's CoolClient backdoor gaining a kernel-mode rootkit that blinds EDR tools — a significant stealth upgrade for this China-linked APT targeting government and diplomatic entities.

Summary written by editorial AI · Source link below

Filed by Securelist (Kaspersky)1 min readRead at source ↗

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Editorial Analysis

Why it matters

The addition of kernel-level evasion to a known APT toolkit means that organisations relying solely on userland EDR may miss active compromises, especially in sectors historically targeted by HoneyMyte.

What to do

Verify that endpoint protection includes kernel-integrity monitoring and driver-load auditing, and hunt for published CoolClient IOCs across your estate.

Board brief

A state-linked APT group has added kernel-level rootkit capabilities that can evade standard endpoint security tools.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Securelist (Kaspersky)

External link — opens at Securelist (Kaspersky) in a new tab.

§
Continue with

More from the Threat Intel Desk