Find notable cyber news and cases, enriched with sources, timelines, and signals.

HoneyMyte PlugX campaign targeting Myanmar

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity shows a coordinated intrusion chain with Microsoft Defender exclusions, DLL sideloading, and startup persistence. It also sits within a broader set of victims seen across Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities.

Related Happenings

UAT-10147 global Windows and Linux web server targeting campaign

Campaign
H score37 First: 27.08.2026 10:05 Last: 27.08.2026 10:05 Sources 1

About this happening: The UAT-10147 campaign is targeting Windows and Linux web servers globally, increasing exposure for education, media, technology, and gaming organizations....

COOLCLIENT updated backdoor deploying Msagent.sys

Malware Activity
H score23 First: 24.08.2026 14:51 Last: 24.08.2026 14:51 Sources 1

About this happening: The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is t...

Microsoft Defender BTR.sys reverse engineering shows a signed boot-time driver can be used for kernel-level file and registry operations

Technical Analysis
H score27 First: 21.08.2026 18:52 Last: 21.08.2026 18:52 Sources 1

About this happening: BTR.sys has been shown to function as a kernel-level file and registry operation primitive on Windows 7 through Windows 11 25H2, creating a new hardening and detection...

MoYu Group campaign expands across multiple victims

Campaign
H score43 First: 21.08.2026 18:41 Last: 21.08.2026 18:41 Sources 1

About this happening: Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, wi...

Chinese-speaking threat actor Central Asia government campaign

Campaign
H score29 First: 31.07.2026 21:52 Last: 31.07.2026 21:52 Sources 1

About this happening: The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...

Timeline

  1. 14.08.2026 16:08 2 articles · 13d ago

    HoneyMyte deploys an updated CoolClient backdoor with a signed Windows kernel-mode rootkit

    Initial Disclosure

    Kaspersky reported that HoneyMyte (aka Mustang Panda) is deploying an updated CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide malicious processes, files, registry objects, and C2 network information. The activity was seen in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, and CoolClient is consistently used as a secondary backdoor after PlugX. Kaspersky also published file hashes, paths, and C2 domains as indicators of compromise.

    Show sources