HoneyMyte PlugX campaign targeting Myanmar
Campaign
Summary
Hide ▲
Show ▼
The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity shows a coordinated intrusion chain with Microsoft Defender exclusions, DLL sideloading, and startup persistence. It also sits within a broader set of victims seen across Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities.
Related Happenings
Chinese-speaking threat actor Central Asia government campaign
Campaign
H score29
First: 31.07.2026 21:52
Last: 31.07.2026 21:52
Sources 1
About this happening:
The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...
Chinese-speaking threat actor Central Asia government campaign
CampaignAbout this happening: The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
OP-512 Microsoft IIS espionage campaign
Campaign
H score52
First: 05.06.2026 15:33
Last: 05.06.2026 15:33
Sources 1
About this happening:
OP-512 is an active espionage campaign targeting Microsoft IIS servers with a bespoke web shell framework, increasing the risk of stealthy remote access on exposed...
OP-512 Microsoft IIS espionage campaign
CampaignAbout this happening: OP-512 is an active espionage campaign targeting Microsoft IIS servers with a bespoke web shell framework, increasing the risk of stealthy remote access on exposed...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
Timeline
-
14.08.2026 16:08 2 articles · 2d ago
HoneyMyte deploys an updated CoolClient backdoor with a signed Windows kernel-mode rootkit
Initial DisclosureKaspersky reported that HoneyMyte (aka Mustang Panda) is deploying an updated CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide malicious processes, files, registry objects, and C2 network information. The activity was seen in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, and CoolClient is consistently used as a secondary backdoor after PlugX. Kaspersky also published file hashes, paths, and C2 domains as indicators of compromise.
Show sources
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth — thehackernews.com — 14.08.2026 16:08
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth — thehackernews.com — 14.08.2026 16:08