
HoneyMyte CoolClient Rootkit Hooks Windows Nsiproxy to Conceal C2 Addresses
The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode rootkit that hides command-and-control (C2) infrastructure on compromised Windows systems. The new capability marks a major shift for the malware, which was previously known mainly as a user-mode espionage tool. CoolClient has been linked to HoneyMyte campaigns targeting […]
The post HoneyMyte CoolClient Rootkit Hooks Windows Nsiproxy to Conceal C2 Addresses appeared first on Cyber Security News.