BR100 Decreased By (-1.72%)
BR30 Decreased By (-2.68%)
KSE100 Decreased By (-1.36%)
KSE30 Decreased By (-1.26%)
AGHA 6.40 Decreased By ▼ -0.18 (-2.74%)
BECO 4.34 Decreased By ▼ -0.04 (-0.91%)
BML 54.69 Decreased By ▼ -0.84 (-1.51%)
BOP 28.80 Decreased By ▼ -1.13 (-3.78%)
CNERGY 12.21 Decreased By ▼ -0.51 (-4.01%)
CSIL 5.00 Decreased By ▼ -0.20 (-3.85%)
FCCL 50.00 Decreased By ▼ -1.13 (-2.21%)
FFL 13.80 Decreased By ▼ -0.61 (-4.23%)
FNEL 1.16 Decreased By ▼ -0.06 (-4.92%)
KEL 5.60 Decreased By ▼ -0.37 (-6.2%)
KOSM 5.35 Decreased By ▼ -0.22 (-3.95%)
LOTCHEM 25.24 Decreased By ▼ -1.01 (-3.85%)
MLCF 88.44 Decreased By ▼ -1.70 (-1.89%)
NBP 156.85 Decreased By ▼ -5.26 (-3.24%)
NCPL 51.30 Decreased By ▼ -1.32 (-2.51%)
NPL 54.38 Decreased By ▼ -3.60 (-6.21%)
OGDC 310.46 Decreased By ▼ -4.16 (-1.32%)
PACE 9.13 Decreased By ▼ -0.57 (-5.88%)
PAEL 33.24 Decreased By ▼ -1.53 (-4.4%)
PIBTL 13.25 Decreased By ▼ -0.95 (-6.69%)
PPL 217.50 Decreased By ▼ -3.16 (-1.43%)
PRL 87.30 Decreased By ▼ -3.05 (-3.38%)
PTC 56.80 Decreased By ▼ -2.07 (-3.52%)
SSGC 22.42 Decreased By ▼ -0.85 (-3.65%)
TBL 8.63 Decreased By ▼ -0.04 (-0.46%)
TELE 7.03 Decreased By ▼ -0.33 (-4.48%)
TPL 20.30 Decreased By ▼ -0.72 (-3.43%)
TPLP 11.50 Decreased By ▼ -0.60 (-4.96%)
TREET 20.41 Decreased By ▼ -0.95 (-4.45%)
TRG 51.00 Decreased By ▼ -3.39 (-6.23%)

ISLAMABAD: A global cyber security company has discovered an updated malware that gives cyber attackers remote access in intrusions targeting organizations and government entities in Myanmar, Mongolia, Pakistan, India and also Russia.

According to the report of the company, Kaspersky Global Research and Analysis Team (GReAT) has identified a new CoolClient variant linked to HoneyMyte APT, also known as Mustang Panda, in a 2026 cyber-espionage campaign across Asia and Russia. The malware uses a signed kernel driver, software that runs deep in the system to hide on infected Windows devices. In the observed campaign the actor used PlugX, another backdoor commonly deployed after an initial breach, to deliver the CoolClient components.

The latest CoolClient variant is designed to operate with a stealthy profile and make remediation more difficult. It deploys a signed driver that runs deep within Windows to help hide the malware’s presence, protect related files and registry entries from inspection or modification and support the backdoor’s activity on the infected system.

To maintain access after a reboot, the attacker created a scheduled task that launched defender.exe automatically at startup with the highest local Windows privileges. When executed, it loaded a malicious libngs.dll file triggering the CoolClient infection chain.

For the targeted organization, that means the malware can remain active on a compromised system while masking key traces of its presence and limiting defenders’ ability to inspect or remove it,” said Fareed Radzi, Security Researcher at Kaspersky GReAT, the report added.

Copyright Business Recorder, 2026

Comments

200 characters remaining