
HoneyMyte APT Deploys Upgraded CoolClient Backdoor in Targeted Asian Espionage Campaign
Kaspersky researchers have identified a sophisticated cyber-espionage operation by HoneyMyte, utilizing an evolved CoolClient backdoor to infiltrate government and telecommunications sectors across Southeast Asia.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Southeast Asia
- Confidence:
- High Confidence
- Source:
- Kaspersky GReAT
- Read Time:
- 5 min
Executive Summary
On August 14, 2026, security researchers at Kaspersky's Global Research and Analysis Team (GReAT) released findings regarding a renewed espionage campaign attributed to the HoneyMyte APT group. The campaign features an upgraded version of the 'CoolClient' backdoor, specifically targeting high-value entities in Asia. This activity represents a significant escalation in the group's technical capabilities, focusing on long-term persistence and stealthy data exfiltration from government, diplomatic, and telecommunications infrastructure. The discovery highlights the persistent threat posed by state-sponsored actors in the region, particularly as geopolitical tensions continue to drive intelligence requirements.
Threat Analysis
HoneyMyte, also known as Mustang Panda or TA416, has historically focused on Southeast Asian government and diplomatic targets to support regional strategic interests. According to Kaspersky: HoneyMyte deploys upgraded CoolClient backdoor in cyber-espionage campaign across Asia, this latest iteration shows a marked shift in Tactics, Techniques, and Procedures (TTPs). The group has moved away from generic malware in favor of highly customized tools designed to bypass modern Endpoint Detection and Response (EDR) solutions. The campaign appears to be part of a broader trend of increased espionage activity in the region, similar to recent operations by groups like Armored Likho, which have begun targeting communication platforms like Telegram for eavesdropping as noted in New Armored Likho tools target Telegram and eavesdropping.
Technical Details
The infection chain typically begins with highly targeted spear-phishing emails containing malicious attachments or links to compromised websites. Once a user interacts with the lure, the group employs DLL side-loading—a technique where a legitimate executable is used to load a malicious DLL—to evade detection. The 'CoolClient' backdoor itself is a modular piece of malware capable of performing a wide range of tasks, including file system manipulation, process management, and the execution of arbitrary commands. A key feature of the upgraded version is its enhanced communication protocol, which uses multi-layered encryption to hide Command and Control (C2) traffic within standard HTTPS requests. The malware also includes sophisticated anti-analysis checks to detect if it is running in a sandbox or virtual machine environment, self-terminating if such conditions are met.
Attribution Assessment
We assess with high confidence that this campaign is the work of HoneyMyte. This attribution is based on significant code overlaps with previous versions of the CoolClient backdoor and the use of infrastructure that has been linked to the group in prior operations. Furthermore, the targeting profile—focusing on specific government ministries and regional telecommunications providers—aligns perfectly with the established intelligence-gathering priorities of this actor. The group's ability to maintain a high operational tempo while evolving its toolset suggests a well-resourced, state-sponsored entity.
Implications
The deployment of the upgraded CoolClient backdoor suggests that HoneyMyte is successfully adapting to improved defensive postures in the region. The focus on telecommunications providers is particularly concerning, as it may allow the group to intercept sensitive communications or gain a foothold for further lateral movement into other critical sectors. This campaign underscores the ongoing risk of strategic intelligence theft, which can provide adversaries with a significant advantage in diplomatic negotiations and regional security planning.
Recommendations
Organizations in the targeted sectors should immediately review their systems for indicators of compromise (IoCs) associated with HoneyMyte. We recommend the deployment of advanced EDR and XDR solutions to provide real-time visibility into suspicious process behaviors, such as unexpected DLL side-loading. Additionally, organizations should implement strict network segmentation and monitor for unusual outbound HTTPS traffic to unknown or suspicious domains. Regular employee training on identifying sophisticated spear-phishing attempts remains a critical line of defense against initial entry.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

New Iranian Cyber Espionage Campaign Targets Global Dissidents and Journalists

NightEagle APT Escalates Cyber Espionage Campaign Against Russian Critical Infrastructure

