CoolClient is a Windows backdoor associated with the China-linked cyberespionage group HoneyMyte, also tracked as Mustang Panda. Publicly documented since 2022, it has been used against organizations across Asia and Russia, including government entities in Myanmar, Mongolia, Pakistan, and Russia. In observed intrusions, it served as a secondary backdoor deployed after attackers established a foothold with PlugX.
CoolClient supports keylogging, clipboard theft, credential harvesting, system reconnaissance, file upload, download and deletion, packet tunneling, and collection of port-mapping information. Plugins extend its functionality, and some variants intercept HTTP traffic for credential collection. Its multi-stage execution chain uses DLL sideloading through legitimate applications, including Sangfor software, to decrypt and load subsequent components into memory. It injects payloads into other processes and establishes persistence through scheduled tasks, registry autorun entries, and Windows services. Variants implement UAC bypass using COM or RPC techniques; newer chains combine RPC-based process creation with parent-process spoofing. Observed deployments also use security-product impersonation and Microsoft Defender exclusions to reduce detection.
Variants investigated in late 2025 and 2026 add a digitally signed Windows kernel-mode rootkit, installed as a driver service when sufficient privileges are available. The backdoor configures the driver through IOCTL requests to register trusted processes, protected filesystem and registry objects, and command-and-control addresses. The driver hides processes, filters filesystem and registry access, restricts access to protected processes, and filters network information returned to user-mode tools to conceal selected command-and-control connections. These mechanisms impede inspection, termination, and removal. CoolClient can continue operating without the driver when the privileges required for its installation are unavailable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A critical pre-authentication remote code execution vulnerability, CVE-2025-15467 (CVSS 9.8), affects OpenSSL versions 3.0, 3.3, 3.4, 3.5, and 3.6.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows.
This includes an unreported cluster dubbed SteppeDriver that was first discovered in 2024 and has since targeted entities in France, Mongolia, and South America using tools like ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Для закрепления в системе атакующие создавали задачу планировщика, которая запускала defender.exe с правами SYSTEM при каждом старте Windows.
The latter handles persistence, registry modifications... The rootkit loads its stealth configuration from \REGISTRY\MACHINE\SYSTEM\RNG and uses separate configuration entries for directories, files, registry keys and values, and processes that should be hidden, protected, or ignored.
Для закрепления в системе атакующие создавали задачу планировщика, которая запускала defender.exe с правами SYSTEM при каждом старте Windows.
Остальные, среди прочего, поддерживают скрытие процессов и модулей ядра, внедрение шелл-кода, снятие защиты PPL и запись по произвольному адресу в памяти ядра.
It also implements a remote procedure call (RPC)-based process creation technique combined with parent process ID (PPID) spoofing to relaunch itself in an elevated context before injecting into a process named synchost.exe.
The driver enhances the malware's stealth by hiding the COOLCLIENT process, protecting related files and registry entries, and preventing them from being inspected or modified
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading... before injecting into a process named synchost.exe.
Création d’un faux dossier Windows Defender ... une application légitime Sangfor renommée en defender.exe ... processus nommé synchost.exe
Остальные, среди прочего, поддерживают скрытие процессов и модулей ядра, внедрение шелл-кода, снятие защиты PPL и запись по произвольному адресу в памяти ядра.
Files get similar treatment through a Windows filesystem minifilter. The driver maintains protected path lists and checks filesystem activity against them, denying access to matching files and directories.
It also implements a remote procedure call (RPC)-based process creation technique combined with parent process ID (PPID) spoofing to relaunch itself in an elevated context before injecting into a process named synchost.exe.
The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests. The driver enhances the malware’s stealth by hiding the CoolClient process, protecting related files and registry entries, and preventing them from being inspected or modified.
The latter handles persistence, registry modifications... The rootkit loads its stealth configuration from \REGISTRY\MACHINE\SYSTEM\RNG and uses separate configuration entries for directories, files, registry keys and values, and processes that should be hidden, protected, or ignored.
Kaspersky documented another evolution in 2025, when the malware gained clipboard theft and HTTP traffic interception for credential harvesting.
Kaspersky documented another evolution in 2025, when the malware gained clipboard theft and HTTP traffic interception for credential harvesting.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A known backdoor, first detected in 2022, associated here with Mustang Panda. The updated variant can deploy a signed kernel-mode driver to improve stealth by hiding the process and protecting files and registry entries; it also supports keylogging, clipboard theft, credential harvesting, file management, reconnaissance, and plugin-based extensions.
Backdoor used by HoneyMyte in espionage campaigns. It can log keystrokes, capture clipboard contents, steal credentials, manipulate files, collect system information, and be extended via plugins. The updated version uses a signed Windows kernel-mode driver (msagent.sys) to hide and protect processes, files, and registry objects, filter network data, and effectively add rootkit capabilities.
Backdoor/implant used by HoneyMyte, updated with a signed kernel-mode rootkit component to hide processes, files, registry keys, and C2 traffic, while protecting the CoolClient process from termination or code injection.
Windows backdoor used for keystroke logging, clipboard theft, credential collection, system reconnaissance and file operations. The upgraded variant deploys the signed msagent.sys kernel driver to conceal processes, files, registry entries and command-and-control connections, and to obstruct inspection or termination. It uses DLL sideloading and persistence through scheduled tasks, AutoRun entries and services. The reported activity targeted organizations in Pakistan, Mongolia, Myanmar and Russia.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.