HoneyMyte Targets Pakistan, Asia in Updated Cyber-Espionage Campaign
Cybersecurity researchers at Kaspersky GReAT have uncovered an updated version of the CoolClient backdoor, linked to the HoneyMyte advanced persistent threat (APT) group, also known as Mustang Panda.

Kaspersky uncovers an updated CoolClient malware campaign targeting organisations across Asia.
Islamabad: Cybersecurity researchers at Kaspersky GReAT have uncovered an updated version of the CoolClient backdoor, linked to the HoneyMyte advanced persistent threat (APT) group, also known as Mustang Panda.
The malware has appeared in a 2026 cyber-espionage campaign targeting organisations and government entities across Asia and Russia. The affected countries include Pakistan, Myanmar, Mongolia and India.
Updated Malware Uses Kernel Driver
According to Kaspersky GReAT, the latest CoolClient variant uses a signed kernel driver to operate deep within Windows systems. This technique can help attackers hide malicious activity and make detection and removal more difficult.
Researchers observed the attackers using PlugX, another backdoor associated with HoneyMyte, to deliver CoolClient components after gaining initial access to targeted systems.
The updated malware can protect associated files, processes and registry entries from inspection. It can also filter selected network information, further complicating investigations by cybersecurity teams.
Attackers Exploit Windows Security Settings
Before deploying CoolClient, the attackers modified Microsoft Defender settings to exclude specific files and folders from scanning.
They created a fake Windows Defender directory and placed malicious files inside it. The attackers also renamed a legitimate Sangfor program as defender.exe to help load malicious code.
The campaign used a scheduled task to maintain access after a system reboot. The task launched the renamed executable automatically with high Windows privileges.
Researchers said the executable then loaded a malicious libngs.dll file, triggering the CoolClient infection process.
Turkmenistan Sets Out Priorities for 81st UN General Assembly
Kaspersky Warns Targeted Organisations
Fareed Radzi, Security Researcher at Kaspersky GReAT, said the latest CoolClient version represents a significant development compared with earlier variants.
He said the malware now combines a user-mode backdoor with a kernel-mode driver. This gives attackers additional capabilities to hide processes, files and registry objects while making forensic analysis more difficult.
Kaspersky urged organisations to remain vigilant against indicators of compromise linked to HoneyMyte and the tools identified in its research.
The company recommended using security platforms that provide endpoint protection, detection and response capabilities. It also advised organisations to strengthen threat visibility and incident-response procedures.
For organisations without sufficient cybersecurity expertise, Kaspersky recommended managed security services covering threat identification, continuous monitoring, incident response and remediation.
The discovery highlights the growing sophistication of cyber-espionage campaigns targeting organisations across Asia, including Pakistan, and underlines the importance of stronger endpoint protection and threat monitoring.
