APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
2026-08-17T20:51:46Z•b62348d9d5d235bfcac3a9bd02e1be99abcf8303e0df05652d6a3c45ded9375d
APTAiTMArmored-LikhoC2CoolClientDNS-tunnelingGoogle-Apps-ScriptHead-MareHoneyMyteMFA-bypassOctLurkPhantomCorePhantomGraphProject-CAV3RNSilkLurkКStill-ToolkitTelegramTrueConfWindowsbackdoorcloud-servicescyber-espionagekernel-rootkitphishingrootkit
What happened
Kaspersky Securelist reporting from late July through mid-August 2026 describes multiple cyber-espionage and malware campaigns, including HoneyMyte’s CoolClient backdoor with a kernel-level Windows rootkit, Armored Likho’s Telegram-stealing Still Toolkit, Head Mare exploitation of unpatched TrueConf servers, Project CAV3RN’s Google Apps Script and DNS-based C2, and OctLurk/SilkLurk memory-resident backdoors. Additional reporting covers adversary-in-the-middle phishing bypassing MFA through legitimate cloud platforms, Kerberoasting and DNS tunneling detection, and broader PC, mobile, IoT, and教育
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- b62348d9d5d235bfcac3a9bd02e1be99abcf8303e0df05652d6a3c45ded9375d
- Enrichment time
- 2026-08-17T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.