APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

2026-08-20T20:51:46Zf09f7dde3f8c2501c69c0206e49d39a5b1afb52cfcfffde9c2d4f55ceab20cb0
APTAiTM-phishingArmored-LikhoCentral-AsiaCoolClientDNS-tunnelingGoogle-Apps-ScriptHead-MareHoneyMyteMFA-bypassOctLurkPhantomCorePhantomGraphSilkLurkStill-ToolkitTelegram-targetingTrueConfWindowscloud-hosting-abusecovert-C2credential-theftcyber-espionagekernel-rootkitkeyloggingnetwork-discovery

What happened

Kaspersky Securelist reporting from late July to mid-August 2026 covers multiple cyber-espionage and malware developments: HoneyMyte’s CoolClient backdoor with a kernel-level Windows rootkit; Armored Likho’s Still Toolkit targeting Telegram data and eavesdropping; Head Mare exploitation of unpatched TrueConf servers to deliver PhantomCore and PhantomGraph; Project CAV3RN’s use of Google Apps Script and DNS for covert C2; phishing kits hosted on legitimate cloud platforms to bypass MFA; and OctLurk/SilkLurk backdoors supporting credential theft, network discovery, shells, and keylogging. The 10

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
f09f7dde3f8c2501c69c0206e49d39a5b1afb52cfcfffde9c2d4f55ceab20cb0
Enrichment time
2026-08-20T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.