APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
B Securelist ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
The use of a signed kernel driver as a rootkit shows the group is deliberately bypassing EDR detection on Windows endpoints and servers, not merely exfiltrating data.
Description
The APT actor HoneyMyte is deploying an evolved variant of its CoolClient backdoor that additionally loads a kernel driver as a rootkit. The driver is digitally signed and conceals the backdoor's activity at system level, allowing it to bypass userland-based detection and conventional EDR sensors. CoolClient was first publicly described in 2022 and documented in 2023 through analysis of the Earth Preta campaign; a new stage of evolution has been observed since 2025. The technique targets Windows systems, using mechanisms such as interceptor registration on nsiproxy.sys that have also been seen in other rootkit families. It is an active, state-attributed campaign aimed at long-term, stealthy persistence.
Risk score
- strategic relevance
- 0.82
Path: strategic