ISLAMABAD: A global cyber security company has discovered an updated malware that gives cyber attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia.
According to the report of the company, Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also known as Mustang Panda, in a 2026 cyber-espionage campaign across Asia and Russia. The malware uses a signed kernel driver, software that runs deep in the system to hide on infected Windows devices. In the observed campaign the actor used PlugX, another backdoor commonly deployed after an initial breach, to deliver the CoolClient components.
The latest CoolClient variant is designed to operate with a stealthy profile and make remediation more difficult. It deploys a signed driver that runs deep within Windows to help hide the malware’s presence, protect related files and registry entries from inspection or modification and support the backdoor’s activity on the infected system.
To maintain access after a reboot, the attacker created a scheduled task that launched defender.exe automatically at startup with the highest local Windows privileges. When executed, it loaded a malicious libngs.dll file triggering the CoolClient infection chain.
For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT, the report added.
Copyright Business Recorder, 2026




















Comments