HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections

HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. The development marks a notable escalation in the group’s post-compromise tradecraft, moving protection and evasion below the user-mode layer where many endpoint inspection […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: