Chinese Hacking Group Adds Stealth Rootkit to Evade Detection
Security researchers have identified a new campaign by the threat actor known as HoneyMyte, also called Mustang Panda, involving an updated version of its CoolClient backdoor. The upgraded malware now includes a signed Windows kernel-mode rootkit, a powerful tool that can conceal malicious processes, files, registry entries, and network connections used to communicate with attacker-controlled servers.
Because the rootkit component is digitally signed, it can potentially bypass security checks that rely on trusted certificates, making infections harder to detect using standard antivirus or endpoint monitoring tools. Kaspersky, the cybersecurity vendor that discovered this activity, has identified victims in Myanmar, Mongolia, and Pakistan so far.
While this campaign currently appears focused on specific regions, the techniques involved—particularly the use of signed rootkits to evade detection—represent a growing trend among sophisticated threat actors. Australian businesses, especially those with international supply chain connections or operations in Asia, should be aware that such advanced evasion techniques may eventually be adapted for broader use, including against smaller organisations that serve as entry points into larger networks.