
Mustang Panda Escalates Asian Espionage with Signed Rootkit and Upgraded CoolClient Backdoor
HoneyMyte (Mustang Panda) has deployed an updated CoolClient backdoor featuring a signed Windows kernel-mode rootkit. The campaign targets government entities across Asia and Russia using PlugX for initial delivery.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Asia
- Confidence:
- High Confidence
- Source:
- Kaspersky GReAT
- Read Time:
- 4 min
Executive Summary
Recent intelligence from Kaspersky GReAT reveals a significant escalation in the operations of the China-linked threat actor HoneyMyte, also known as Mustang Panda. As of mid-August 2026, the group is actively deploying an upgraded version of its 'CoolClient' backdoor, now integrated with a signed Windows kernel-mode rootkit. This campaign primarily targets government and diplomatic entities in Myanmar, Mongolia, Pakistan, India, and Russia, signaling a broad intelligence-gathering mandate across the region.
Threat Analysis
The use of a signed kernel driver represents a sophisticated shift in Mustang Panda's tradecraft. By operating at the kernel level, the malware can effectively hide its presence from standard user-mode security tools, including many antivirus and EDR solutions. The rootkit is designed to protect malicious processes, files, and registry keys from detection and deletion, ensuring long-term persistence within compromised networks. This development indicates that the actor has successfully bypassed or subverted the Windows driver signing process, either through stolen certificates or by exploiting weaknesses in the certification authority chain.
Technical Details
The infection chain typically begins with the deployment of the PlugX backdoor, a staple in the group's arsenal, often delivered via spear-phishing or the exploitation of edge vulnerabilities. PlugX is then used to drop the CoolClient components. The centerpiece of this update is the signed kernel driver, which allows the malware to intercept system calls and manipulate the operating system's view of the file system and network connections. The CoolClient backdoor itself provides comprehensive remote access capabilities, including file exfiltration, shell execution, and system monitoring. The integration of the rootkit specifically targets the concealment of command-and-control (C2) network information, making traffic analysis significantly more difficult for defenders.
Attribution Assessment
Analysts attribute this activity to HoneyMyte (Mustang Panda) with high confidence. The attribution is based on the continued use of the PlugX backdoor, specific code overlaps in the CoolClient malware family, and targeting patterns that align with historical Chinese state-sponsored espionage objectives. The group's focus on both traditional regional adversaries and strategic partners like Russia suggests a high-priority mission to monitor geopolitical developments and internal communications within these nations.
Implications
This campaign underscores the persistent threat posed by Mustang Panda to regional government infrastructure. The ability to bypass modern security controls using signed drivers suggests a high level of resource acquisition and technical maturity. The inclusion of Russian targets alongside South Asian nations indicates that the group's intelligence requirements are expanding, potentially reflecting shifting geopolitical alignments in 2026. Organizations in the targeted sectors must assume that standard detection methods may be insufficient against this specific threat.
Recommendations
Encrygma recommends that organizations implement strict driver signing policies and utilize security tools that monitor for unauthorized kernel-mode activity. Enhanced monitoring of PlugX indicators and the implementation of robust EDR solutions capable of detecting kernel-level hooks are essential. Furthermore, network segmentation and strict access controls for administrative accounts can help mitigate the impact of a successful initial breach. Security teams should also audit all installed drivers and revoke trust for any certificates associated with recent HoneyMyte activity.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



