HoneyMyte Hacker Group Expands CoolClient Malware With New Advanced Toolset
## Cybersecurity: HoneyMyte APT Group Expands Operations and Enhances Toolset
Cybersecurity: HoneyMyte APT Group Expands Operations and Enhances Toolset
The HoneyMyte Advanced Persistent Threat (APT) group, also identified as Mustang Panda and Bronze President, has continued its cyber-espionage activities across Asia and Europe, notably targeting Southeast Asia. Recent analysis indicates significant advancements in the group's malware arsenal in 2025, including enhancements to the CoolClient backdoor and the deployment of various browser credential-stealing tools. Government entities remain the primary focus of these sophisticated operations.
Technical Advancements in CoolClient Backdoor
Originally discovered by Sophos in 2022, the CoolClient backdoor has undergone considerable development. The latest version demonstrates substantial functional improvements, delivered via encrypted loader files comprising configuration data, shellcode, and malicious DLL modules leveraging DLL sideloading techniques. Between 2021 and 2025, HoneyMyte exploited legitimate software like Bitdefender, VLC Media Player, Ulead PhotoImpact, and Sangfor for execution.
The updated CoolClient variant utilizes Sangfor applications for DLL sideloading, implementing three operational modes: install mode for persistence, work mode for standard operations, and passuac mode for UAC bypass and privilege escalation. Persistence is achieved through registry modifications and scheduled tasks named ComboxResetTask.
Core functionalities include system data collection, file management, keylogging, TCP tunneling, and reverse proxy capabilities. The 2025 variant introduces clipboard monitoring and HTTP proxy credential sniffing, capturing data via GetClipboardData and GetWindowTextW APIs, and storing encrypted information at C:\ProgramData\AppxProvisioning.xml.
Government entities remain the primary focus of these sophisticated operations.
The HTTP proxy credential sniffer intercepts local network traffic, extracting Proxy-Authorization headers and decoding Base64-encoded credentials for command-and-control server communication.
Recent telemetry has identified three CoolClient plugins: FileMgrS.dll for file management, RemoteShellS.dll for remote command shell access, and ServiceMgrS.dll for Windows service manipulation. These plugins facilitate comprehensive system reconnaissance and data exfiltration.
HoneyMyte also deployed three browser credential stealer variants targeting Chrome, Microsoft Edge, and Chromium-based browsers, extracting login credentials and authentication data. Variant C offers enhanced flexibility, accepting runtime arguments for browser file paths, enabling widespread attacks against Chromium variants.
The malware utilizes Windows DPAPI to decrypt browser master keys and retrieve stored passwords. Complementary scripts, such as batch script 1.bat and PowerShell script Ttraazcs32.ps1, facilitate system enumeration, document theft, and data exfiltration through FTP and Pixeldrain file-sharing services.
Organizations are advised to implement robust detection mechanisms for CoolClient variants, PlugX, ToneShell, and related malware families. Enhanced endpoint monitoring, network traffic analysis, and browser security measures are critical to mitigating these persistent threats.
Based on reporting by GBHackers.
