APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
2026-08-17T08:51:46Z•91811e616c01807fc1c0de12f3d6c294b55300210c6410134d62b955550dcd4a
APTAitM phishingArmored LikhoCoolClientDNS tunnelingGoogle Apps Script C2Head MareHoneyMyteKerberoastingMFA bypassOctLurkPhantomCorePhantomGraphProject CAV3RNSilkLurkStill ToolkitTelegram theftTrueConf exploitationWindows rootkitcloud-based C2credential dumpingcyber espionagekernel rootkitmemory-resident malwareservice workers
What happened
Kaspersky Securelist reporting highlights active APT and cyber-espionage campaigns in August 2026, including a kernel-level Windows rootkit, Telegram surveillance malware, exploitation of unpatched TrueConf servers, cloud-service C2 relays, DNS-based command-and-control, MFA-bypassing adversary-in-the-middle phishing, and memory-resident backdoors capable of credential theft, network discovery, shell execution, and keylogging. The collection also includes broader quarterly threat statistics and incident-response analysis.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 91811e616c01807fc1c0de12f3d6c294b55300210c6410134d62b955550dcd4a
- Enrichment time
- 2026-08-17T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.