Pakistani, Asian Organisations Targeted in HoneyMyte Cyber Attacks

Honeymyte Targets Pakistani Asian Organisations With Advanced Malware

An updated version of the CoolClient backdoor linked to the HoneyMyte APT group, also known as Mustang Panda, has been used in a cyber-espionage campaign targeting organisations and government entities across Pakistan and Asia.

According to Kaspersky, the campaign observed in 2026 affected targets in Myanmar, Mongolia, Pakistan, India and Russia.

The latest CoolClient variant uses a signed kernel driver that allows it to operate deep within Windows systems, making detection, investigation and removal more difficult.

Researchers said the attackers initially used PlugX to deploy CoolClient after compromising targeted systems. They also modified Microsoft Defender settings to exclude malicious files from scanning, created a fake Windows Defender directory and renamed a legitimate Sangfor application as defender.exe to help load the malware.

The attackers established persistence through a scheduled task that launched defender.exe with elevated privileges after system startup. The executable then loaded a malicious libngs.dll file to initiate the infection.

Kaspersky researcher Fareed Radzi said the latest version represents a major evolution of CoolClient, which has developed from a user-mode backdoor into a threat capable of leveraging a kernel-mode driver to conceal system objects and filter network data.

Kaspersky has urged organisations to monitor for indicators of compromise associated with HoneyMyte and strengthen their capabilities for threat detection, investigation, response and remediation.

Get Alerts