APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
2026-08-20T20:51:46Z•f09f7dde3f8c2501c69c0206e49d39a5b1afb52cfcfffde9c2d4f55ceab20cb0
APTAiTM-phishingArmored-LikhoCentral-AsiaCoolClientDNS-tunnelingGoogle-Apps-ScriptHead-MareHoneyMyteMFA-bypassOctLurkPhantomCorePhantomGraphSilkLurkStill-ToolkitTelegram-targetingTrueConfWindowscloud-hosting-abusecovert-C2credential-theftcyber-espionagekernel-rootkitkeyloggingnetwork-discovery
What happened
Kaspersky Securelist reporting from late July to mid-August 2026 covers multiple cyber-espionage and malware developments: HoneyMyte’s CoolClient backdoor with a kernel-level Windows rootkit; Armored Likho’s Still Toolkit targeting Telegram data and eavesdropping; Head Mare exploitation of unpatched TrueConf servers to deliver PhantomCore and PhantomGraph; Project CAV3RN’s use of Google Apps Script and DNS for covert C2; phishing kits hosted on legitimate cloud platforms to bypass MFA; and OctLurk/SilkLurk backdoors supporting credential theft, network discovery, shells, and keylogging. The 10
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- f09f7dde3f8c2501c69c0206e49d39a5b1afb52cfcfffde9c2d4f55ceab20cb0
- Enrichment time
- 2026-08-20T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.