APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
AI Summary
The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode Windows rootkit to enhance stealth and persistence. The new variant uses a signed kernel driver, msagent.sys, deployed as a Windows service to hide malicious processes, files, registry keys, and network connections. The malware chain begins with DLL sideloading via a renamed Sangfor executable (defender.exe), establishes persistence through scheduled tasks and registry entries, performs UAC bypass using RPC techniques, and injects into synchost.exe before deploying the driver. The driver communicates with user-mode components via IOCTLs and employs minifilter and registry callbacks to protect its artifacts.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 22 extracted
| Type | Value | Detail |
|---|---|---|
| MD5 | 2d7c8780e97409770a9d4f31c66c9d63 | Details → |
| SHA-1 | 9460e150e1981d5c165043520c5c12fe | Details → |
| MD5 | 9717f005c5fb98e08d2ad983d88f94ee | Details → |
| SHA-1 | f518d8e5fe70d9090f6280c68a95998f | Details → |
| SHA-1 | eb79558b037669792652a816e2c669de | Details → |
| Filename | msagent.sys | Details → |
| Filename | libngs.dll | Details → |
| Filename | ctxmui.dll | Details → |
| Filename | defender.exe | Details → |
| Filename | loadcert.ini | Details → |
| Filename | cert.ini | Details → |
| Filename | time.ini | Details → |
| Domain | cloudtroe[.]giize[.]com | Details → |
| Domain | employers[.]theworkpc[.]com | Details → |
| Domain | freeread[.]casacam[.]net | Details → |
| Domain | us[.]lenovoappstore[.]com | Details → |
| Domain | sundanish[.]freeddns[.]org | Details → |
| Domain | torinarlabs[.]webredirect[.]org | Details → |
| Domain | news[.]dursamjbataar[.]org | Details → |
| Domain | video[.]dursamjbataar[.]org | Details → |
| Domain | black-popular[.]com | Details → |
| Domain | whatismybestthing[.]com | Details → |