The hacker group HoneyMyte used an updated version of the CoolClient backdoor in cyber espionage campaigns in 2026. Government and commercial organizations in Russia, as well as Myanmar, Mongolia, Pakistan, and India, were targeted. This was reported by specialists from Kaspersky Lab's Global Research and Analysis Center.
CoolClient has been known since 2022, but the new version has significantly more stealthy operating mechanisms. The malicious program uses a signed Windows kernel driver, which helps mask processes, files, and registry entries, and also complicates the analysis of network activity.
To deliver the backdoor, the attackers used PlugX. Before infection, they added exclusions to Microsoft Defender, then created a directory mimicking the Windows security software folder. CoolClient components were placed in it, and the legitimate Sangfor program was renamed to defender.exe.
To maintain access after reboot, the hackers created a scheduled task with maximum local privileges. It launched the malicious chain when the system started.
According to experts, CoolClient's transition to operating through a kernel driver significantly complicates the detection and removal of the threat, as it allows hiding key signs of malware presence.