Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

HoneyMyte Hacker Group Expands CoolClient Malware With New Advanced Toolset

## Cybersecurity: HoneyMyte APT Group Expands Operations and Enhances Toolset

Cybersecurity: HoneyMyte APT Group Expands Operations and Enhances Toolset

The HoneyMyte Advanced Persistent Threat (APT) group, also identified as Mustang Panda and Bronze President, has continued its cyber-espionage activities across Asia and Europe, notably targeting Southeast Asia. Recent analysis indicates significant advancements in the group's malware arsenal in 2025, including enhancements to the CoolClient backdoor and the deployment of various browser credential-stealing tools. Government entities remain the primary focus of these sophisticated operations.

Technical Advancements in CoolClient Backdoor

Originally discovered by Sophos in 2022, the CoolClient backdoor has undergone considerable development. The latest version demonstrates substantial functional improvements, delivered via encrypted loader files comprising configuration data, shellcode, and malicious DLL modules leveraging DLL sideloading techniques. Between 2021 and 2025, HoneyMyte exploited legitimate software like Bitdefender, VLC Media Player, Ulead PhotoImpact, and Sangfor for execution.

The updated CoolClient variant utilizes Sangfor applications for DLL sideloading, implementing three operational modes: install mode for persistence, work mode for standard operations, and passuac mode for UAC bypass and privilege escalation. Persistence is achieved through registry modifications and scheduled tasks named ComboxResetTask.

Core functionalities include system data collection, file management, keylogging, TCP tunneling, and reverse proxy capabilities. The 2025 variant introduces clipboard monitoring and HTTP proxy credential sniffing, capturing data via GetClipboardData and GetWindowTextW APIs, and storing encrypted information at C:\ProgramData\AppxProvisioning.xml.

Government entities remain the primary focus of these sophisticated operations.
John Mason · Thehackingpost

The HTTP proxy credential sniffer intercepts local network traffic, extracting Proxy-Authorization headers and decoding Base64-encoded credentials for command-and-control server communication.

Recent telemetry has identified three CoolClient plugins: FileMgrS.dll for file management, RemoteShellS.dll for remote command shell access, and ServiceMgrS.dll for Windows service manipulation. These plugins facilitate comprehensive system reconnaissance and data exfiltration.

HoneyMyte also deployed three browser credential stealer variants targeting Chrome, Microsoft Edge, and Chromium-based browsers, extracting login credentials and authentication data. Variant C offers enhanced flexibility, accepting runtime arguments for browser file paths, enabling widespread attacks against Chromium variants.

Advertisement

The malware utilizes Windows DPAPI to decrypt browser master keys and retrieve stored passwords. Complementary scripts, such as batch script 1.bat and PowerShell script Ttraazcs32.ps1, facilitate system enumeration, document theft, and data exfiltration through FTP and Pixeldrain file-sharing services.

Organizations are advised to implement robust detection mechanisms for CoolClient variants, PlugX, ToneShell, and related malware families. Enhanced endpoint monitoring, network traffic analysis, and browser security measures are critical to mitigating these persistent threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories