MEDIUMApt
Global

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

·Source: Securelist (Kaspersky)

Updated:

Executive Summary

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Analysis

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Source Attribution

Originally published by Securelist (Kaspersky) on Aug 14, 2026.

Related Threats