APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

2026-08-16T20:51:45Z9ab7e506f14cad1d4162f5d6315e96f85d29930d68bb43aac46f2612cf58cbd8
APTAiTM-phishingBrazilC2Central AsiaDNS tunnelingGoogle Apps ScriptIsraelKerberoastingMFA-bypassPhantomCorePhantomGraphTelegram-stealingTrueConfWindowsbackdoorcloud-abusecredential-dumpingcyber-espionagekernel-modekeyloggingmalware-trendsmemory-resident-malwarerootkitunpatched-vulnerability

What happened

Kaspersky Securelist reporting from late July to mid-August 2026 describes multiple cyber-espionage and malware campaigns, including HoneyMyte’s CoolClient backdoor with a kernel-level Windows rootkit, Armored Likho’s Telegram-stealing Still Toolkit, Head Mare exploitation of unpatched TrueConf servers to deploy PhantomCore and PhantomGraph, Project CAV3RN’s Google Apps Script and DNS-based C2, and OctLurk/SilkLurk memory-resident backdoors targeting Central Asia. Additional reporting covers adversary-in-the-middle phishing that bypasses MFA through legitimate cloud platforms, Kerberoasting, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
9ab7e506f14cad1d4162f5d6315e96f85d29930d68bb43aac46f2612cf58cbd8
Enrichment time
2026-08-16T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.