Find notable cyber news and cases, enriched with sources, timelines, and signals.

HoneyMyte PlugX campaign targeting Myanmar

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity shows a coordinated intrusion chain with Microsoft Defender exclusions, DLL sideloading, and startup persistence. It also sits within a broader set of victims seen across Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities.

Related Happenings

Chinese-speaking threat actor Central Asia government campaign

Campaign
H score29 First: 31.07.2026 21:52 Last: 31.07.2026 21:52 Sources 1

About this happening: The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

OP-512 Microsoft IIS espionage campaign

Campaign
H score52 First: 05.06.2026 15:33 Last: 05.06.2026 15:33 Sources 1

About this happening: OP-512 is an active espionage campaign targeting Microsoft IIS servers with a bespoke web shell framework, increasing the risk of stealthy remote access on exposed...

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

Timeline

  1. 14.08.2026 16:08 2 articles · 2d ago

    HoneyMyte deploys an updated CoolClient backdoor with a signed Windows kernel-mode rootkit

    Initial Disclosure

    Kaspersky reported that HoneyMyte (aka Mustang Panda) is deploying an updated CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide malicious processes, files, registry objects, and C2 network information. The activity was seen in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, and CoolClient is consistently used as a secondary backdoor after PlugX. Kaspersky also published file hashes, paths, and C2 domains as indicators of compromise.

    Show sources