Find notable cyber news and cases, enriched with sources, timelines, and signals.

COOLCLIENT updated backdoor deploying Msagent.sys

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is tied to Mustang Panda and was observed in operations spanning Myanmar, Mongolia, Pakistan, and Russia. The malware's expanded kernel-mode layer makes inspection and remediation harder while preserving its backdoor functionality.

Related Happenings

DoFun Android head unit malware spread through built-in updaters

Malware Activity
H score31 First: 21.08.2026 18:41 Last: 21.08.2026 18:41 Sources 1

About this happening: Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...

HoneyMyte PlugX campaign targeting Myanmar

Campaign
H score32 First: 14.08.2026 16:08 Last: 14.08.2026 16:08 Sources 1

About this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...

Mistic backdoor deployment via ClickFix and DLL side-loading

Malware Activity
H score22 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...

SprySOCKS Windows backdoor activity against government organizations

Malware Activity
H score23 First: 16.06.2026 12:00 Last: 16.06.2026 12:00 Sources 1

About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...

ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance

Technical Analysis
H score34 First: 16.06.2026 12:00 Last: 16.06.2026 12:00 Sources 1

About this happening: ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS...

Timeline

  1. 24.08.2026 14:51 2 articles · 9h ago

    Mustang Panda's COOLCLIENT adds the signed Msagent.sys driver

    Technical Analysis Update

    Mustang Panda's updated COOLCLIENT backdoor deploys a signed kernel-mode driver, Msagent.sys, that hides the COOLCLIENT process, protects related files and registry entries, and makes inspection or modification harder. The backdoor is assessed to be delivered via PlugX using DLL sideloading and was detected in intrusions across Myanmar, Mongolia, Pakistan, and Russia.

    Show sources