APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
2026-08-16T20:51:45Z•9ab7e506f14cad1d4162f5d6315e96f85d29930d68bb43aac46f2612cf58cbd8
APTAiTM-phishingBrazilC2Central AsiaDNS tunnelingGoogle Apps ScriptIsraelKerberoastingMFA-bypassPhantomCorePhantomGraphTelegram-stealingTrueConfWindowsbackdoorcloud-abusecredential-dumpingcyber-espionagekernel-modekeyloggingmalware-trendsmemory-resident-malwarerootkitunpatched-vulnerability
What happened
Kaspersky Securelist reporting from late July to mid-August 2026 describes multiple cyber-espionage and malware campaigns, including HoneyMyte’s CoolClient backdoor with a kernel-level Windows rootkit, Armored Likho’s Telegram-stealing Still Toolkit, Head Mare exploitation of unpatched TrueConf servers to deploy PhantomCore and PhantomGraph, Project CAV3RN’s Google Apps Script and DNS-based C2, and OctLurk/SilkLurk memory-resident backdoors targeting Central Asia. Additional reporting covers adversary-in-the-middle phishing that bypasses MFA through legitimate cloud platforms, Kerberoasting, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 9ab7e506f14cad1d4162f5d6315e96f85d29930d68bb43aac46f2612cf58cbd8
- Enrichment time
- 2026-08-16T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.