Kaspersky reveals upgraded HoneyMyte cyber-espionage campaign targeting Pakistan, Asia and Russia

Kaspersky reveals upgraded HoneyMyte cyber-espionage campaign targeting Pakistan, Asia and Russia

ISLAMABAD: Cybersecurity researchers have uncovered an upgraded malware campaign targeting organizations and government entities in Pakistan and several other countries, with attackers using more sophisticated tools to remain hidden inside compromised Windows systems.

Kaspersky’s Global Research and Analysis Team (GReAT) said the campaign has been linked to HoneyMyte, an advanced persistent threat group also known as Mustang Panda, and involves a newly enhanced version of the CoolClient backdoor.

The cyber-espionage activity observed during 2026 has affected targets in Pakistan, Myanmar, Mongolia, India and Russia, according to the cybersecurity company.

CoolClient is a type of backdoor malware that can give attackers remote access to infected computers, allowing them to maintain a presence inside targeted networks and potentially gather sensitive information.

New CoolClient malware becomes harder to detect

Kaspersky researchers said the latest CoolClient variant represents a significant technical upgrade because it uses a signed kernel driver — software capable of operating at a deep level within the Windows operating system.

The driver can help conceal malicious processes, files and registry entries while making it more difficult for cybersecurity teams to investigate or remove the infection.

According to researchers, the attackers used PlugX, another backdoor frequently associated with targeted cyber-espionage operations, to deploy CoolClient components after gaining access to victim systems.

Earlier Kaspersky research found HoneyMyte using CoolClient and other tools in espionage operations across Asia and Europe, with government entities among its main targets.

Attackers manipulated Microsoft Defender settings

Researchers examining the latest attack chain found that the threat actor altered Microsoft Defender settings before installing the malware.

The attackers reportedly configured the security software to ignore a particular folder and file, allowing malicious components to operate with a lower risk of being detected.

They then created a fake Windows Defender directory and placed CoolClient files inside it.

A legitimate program developed by Sangfor was renamed defender.exe and used to load malicious code through a technique that takes advantage of trusted software to execute an attacker-controlled DLL file.

The attackers also established a scheduled Windows task to automatically run defender.exe whenever the computer restarted.

Because the task was configured with elevated local privileges, the malware could reload after rebooting and continue the CoolClient infection chain through a malicious file identified as libngs.dll.

This persistence mechanism could allow attackers to retain access even after a targeted user restarts the affected computer.

Malware designed to hide evidence of compromise

Fareed Radzi, security researcher at Kaspersky GReAT, said the latest CoolClient version marks an important evolution from previous forms of the malware.

Unlike earlier variants operating primarily as a user-level backdoor, the updated malware communicates with a kernel-mode driver capable of hiding and protecting processes, files and registry objects.

It can also filter certain network information, making both detection and forensic analysis more difficult.

For targeted organizations, researchers warned, this means attackers could potentially remain active on compromised computers while concealing important indicators that security teams would normally use to identify and remove an intrusion.

Why the HoneyMyte campaign matters for Pakistan

The inclusion of Pakistani organizations among the observed targets highlights the continuing cyber-espionage threat facing government departments, businesses and institutions holding sensitive digital information.

Advanced persistent threat groups typically differ from ordinary cybercriminals because their operations are designed to maintain long-term access to selected networks, gather intelligence and avoid detection rather than simply cause immediate disruption.

HoneyMyte has previously been associated with a range of cyber-espionage tools, including PlugX, ToneShell, CoolClient, Tonedisk and SnakeDisk, according to Kaspersky research.

The group has also used techniques such as DLL sideloading, data-stealing scripts and malware designed to collect system and user information.

Kaspersky said organizations should closely monitor indicators of compromise linked to HoneyMyte and maintain threat-detection, endpoint protection and incident-response capabilities capable of identifying suspicious activity at different levels of a system.

Cybersecurity teams should also review security-product exclusions, unusual scheduled tasks, unexpected changes to Windows Defender settings and suspicious executables operating from system directories.

Security specialists additionally recommend maintaining visibility across endpoints and networks, applying security updates promptly and investigating unusual privileged activity before attackers have an opportunity to establish persistent access.

Kaspersky published further technical analysis and indicators related to HoneyMyte and CoolClient through its Securelist threat-research platform.