HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders.

It gives intruders tools designed to survive ordinary security checks. The activity targeted organizations in Pakistan, Mongolia, Myanmar and Russia, including government entities.

In Myanmar, attackers first used PlugX, then installed CoolClient as a second backdoor.

The sequence resembles PlugX USB worm activity reported in other campaigns, where a trusted program is abused to start malicious code. It also shows the group is layering tools rather than relying on one implant.

Researchers from Securelist identified the new variant during late 2025 and 2026 investigations. 

Securelist said in a report shared with Cyber Security News (CSN) that the driver can hide processes, files, registry entries and selected command-and-control connections, giving HoneyMyte more concealment on compromised Windows devices.

This is significant because kernel components operate below monitoring utilities.

It moves part of the operation into Windows kernel mode, where it can interfere with what security tools see. That helps attackers gather intelligence and move inside a victim environment.

HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit

The infection chain starts after PlugX has already established a foothold. Attackers create a fake Windows Defender folder, add exclusions for that folder and a renamed executable, then use a legitimate Sangfor application renamed as defender.exe to load the malicious libngs.dll file.

This DLL sideloading uses a real program as cover and is described in the reported Mustang Panda campaign alongside repeated misuse of trusted applications.

A scheduled task can launch the renamed program with SYSTEM privileges at startup. CoolClient also creates an AutoRun entry and, in some cases, a service called media_updaten.

Overview of the new variant of CoolClient (Source – Securelist)

It injects its code into a process named synchost.exe, an unusual spelling that can look close enough to a normal Windows process to escape a hurried review.

With administrator rights, the malware decrypts and writes its driver as msagent.sys, then installs it as a Windows driver service.

Although the driver carries a digital signature, that signature should not be treated as proof of safety. The certificate was issued to Nanjing Ranyi Technology Co., Ltd. and had expired years before the observed campaign.

The driver receives instructions through a direct Windows communication channel.

It registers CoolClient as trusted, records the installation path and service registry location, and accepts the configured command server address.

This protects malware files while denying other processes access. Similar abuse appears in new Windows backdoor findings, reinforcing why trusted filenames alone are weak evidence.

Msagent.sys uses several Windows callbacks to watch processes, loaded code, files and registry activity. It can reduce the rights other programs receive when they try to open the protected CoolClient process.

That can block termination, inspection and code injection attempts, leaving the backdoor active even when an analyst has identified the suspicious process.

Its file-system filter hides chosen folders and files by denying access during normal operations.

A separate registry callback removes protected keys and values from enumeration results, while refusing attempts to open, change or delete them.

Function to check for running 360 Total Security software processes (Source – Securelist)

The driver can also unlink a process from Windows active-process listings, so a basic task list may not show it.

The rootkit hooks the Windows Nsiproxy driver and removes registered command-and-control IP addresses from network data returned to user-mode tools.

A defender may inspect connections and miss the backdoor address. HoneyMyte used a comparable approach in the earlier HoneyMyte rootkit report, suggesting an established effort to improve long-term concealment.

Teams should treat unexpected driver services, fake security-product directories, unusual Defender exclusions and mismatched DLLs beside legitimate applications as priority leads.

Security teams should investigate scheduled tasks and AutoRun entries that launch defender.exe or Sang.exe from unusual locations, verify driver signatures and certificate status, and collect kernel-level telemetry rather than relying only on user-mode process and network views.

The backdoor is built to spy and make investigation unreliable for responders.

Indicators of Compromise (IoCs):-

Type Indicator Description
File name msagent.sys Kernel-mode rootkit driver deployed by CoolClient
File name libngs.dll First-stage malicious DLL sideloaded by the renamed Sangfor application
File name ctxmui.dll File indicator listed in the source report
File path C:Program Filesmicrosoftwindows defender Fake Windows Defender installation directory
File path C:Program Fileswindows media playermediares Directory indicator listed in the source report
File path C:ProgramDatasymantecdir Directory indicator listed in the source report
File path C:ProgramDatavirtualstore Directory indicator listed in the source report
File path C:Windowsidentitycrlproduction Directory indicator listed in the source report
File path C:Windowsserviceprofilesnetworkservice Directory indicator listed in the source report
File path C:Users<user>AppDataLocalviber24.8 User-profile directory indicator
File path C:Users<user>AppDataRoamingdsassistant User-profile directory indicator
File path C:Program Filescommon filesmicrosoft sharedoffice14 Directory indicator listed in the source report
File path C:programdatamsdn Directory indicator listed in the source report
SHA-1 2d7c8780e97409770a9d4f31c66c9d639460E150 File hash listed in the source report
SHA-224 E1981D5C165043520C5C12FE9717F005C5FB98E08D2AD983D88F94 File hash listed in the source report
SHA-256 EEF518D8E5FE70D9090F6280C68A95998FEB79558B037669792652A816E2C669DE File hash listed in the source report
Domain cloudtroe.giize[.]com Command-and-control or related infrastructure indicator
Domain employers.theworkpc[.]com Command-and-control or related infrastructure indicator
Domain freeread.casacam[.]net Command-and-control or related infrastructure indicator
Domain us.lenovoappstore[.]com Command-and-control or related infrastructure indicator
Domain sundanish.freeddns[.]org Command-and-control or related infrastructure indicator
Domain torinarlabs.webredirect[.]org Command-and-control or related infrastructure indicator
Domain news.dursamjbataar[.]org Command-and-control or related infrastructure indicator
Domain video.dursamjbataar[.]org Command-and-control or related infrastructure indicator
Domain black-popular[.]com Command-and-control or related infrastructure indicator
Domain whatismybestthing[.]com Command-and-control or related infrastructure indicator

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world