APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

2026-08-17T20:51:46Zb62348d9d5d235bfcac3a9bd02e1be99abcf8303e0df05652d6a3c45ded9375d
APTAiTMArmored-LikhoC2CoolClientDNS-tunnelingGoogle-Apps-ScriptHead-MareHoneyMyteMFA-bypassOctLurkPhantomCorePhantomGraphProject-CAV3RNSilkLurkКStill-ToolkitTelegramTrueConfWindowsbackdoorcloud-servicescyber-espionagekernel-rootkitphishingrootkit

What happened

Kaspersky Securelist reporting from late July through mid-August 2026 describes multiple cyber-espionage and malware campaigns, including HoneyMyte’s CoolClient backdoor with a kernel-level Windows rootkit, Armored Likho’s Telegram-stealing Still Toolkit, Head Mare exploitation of unpatched TrueConf servers, Project CAV3RN’s Google Apps Script and DNS-based C2, and OctLurk/SilkLurk memory-resident backdoors. Additional reporting covers adversary-in-the-middle phishing bypassing MFA through legitimate cloud platforms, Kerberoasting and DNS tunneling detection, and broader PC, mobile, IoT, and教育

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b62348d9d5d235bfcac3a9bd02e1be99abcf8303e0df05652d6a3c45ded9375d
Enrichment time
2026-08-17T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.