APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

2026-08-17T08:51:46Z91811e616c01807fc1c0de12f3d6c294b55300210c6410134d62b955550dcd4a
APTAitM phishingArmored LikhoCoolClientDNS tunnelingGoogle Apps Script C2Head MareHoneyMyteKerberoastingMFA bypassOctLurkPhantomCorePhantomGraphProject CAV3RNSilkLurkStill ToolkitTelegram theftTrueConf exploitationWindows rootkitcloud-based C2credential dumpingcyber espionagekernel rootkitmemory-resident malwareservice workers

What happened

Kaspersky Securelist reporting highlights active APT and cyber-espionage campaigns in August 2026, including a kernel-level Windows rootkit, Telegram surveillance malware, exploitation of unpatched TrueConf servers, cloud-service C2 relays, DNS-based command-and-control, MFA-bypassing adversary-in-the-middle phishing, and memory-resident backdoors capable of credential theft, network discovery, shell execution, and keylogging. The collection also includes broader quarterly threat statistics and incident-response analysis.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
91811e616c01807fc1c0de12f3d6c294b55300210c6410134d62b955550dcd4a
Enrichment time
2026-08-17T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit · Baitaphish