COOLCLIENT updated backdoor deploying Msagent.sys
Malware Activity
Summary
Hide ▲
Show ▼
The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is tied to Mustang Panda and was observed in operations spanning Myanmar, Mongolia, Pakistan, and Russia. The malware's expanded kernel-mode layer makes inspection and remediation harder while preserving its backdoor functionality.
Related Happenings
DoFun Android head unit malware spread through built-in updaters
Malware Activity
H score31
First: 21.08.2026 18:41
Last: 21.08.2026 18:41
Sources 1
About this happening:
Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...
DoFun Android head unit malware spread through built-in updaters
Malware ActivityAbout this happening: Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...
HoneyMyte PlugX campaign targeting Myanmar
Campaign
H score32
First: 14.08.2026 16:08
Last: 14.08.2026 16:08
Sources 1
About this happening:
The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
HoneyMyte PlugX campaign targeting Myanmar
CampaignAbout this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware Activity
H score22
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware ActivityAbout this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
SprySOCKS Windows backdoor activity against government organizations
Malware Activity
H score23
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
About this happening:
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SprySOCKS Windows backdoor activity against government organizations
Malware ActivityAbout this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance
Technical Analysis
H score34
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
About this happening:
ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS...
ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance
Technical AnalysisAbout this happening: ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS...
Timeline
-
24.08.2026 14:51 2 articles · 9h ago
Mustang Panda's COOLCLIENT adds the signed Msagent.sys driver
Technical Analysis UpdateMustang Panda's updated COOLCLIENT backdoor deploys a signed kernel-mode driver, Msagent.sys, that hides the COOLCLIENT process, protects related files and registry entries, and makes inspection or modification harder. The backdoor is assessed to be delivered via PlugX using DLL sideloading and was detected in intrusions across Myanmar, Mongolia, Pakistan, and Russia.
Show sources
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor — thehackernews.com — 24.08.2026 14:51
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor — thehackernews.com — 24.08.2026 14:51