HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer
## Cybersecurity: Recent Developments in HoneyMyte's Malware Activities
Cybersecurity: Recent Developments in HoneyMyte's Malware Activities
The HoneyMyte threat group, also identified as Mustang Panda or Bronze President, continues to pose significant security challenges to governmental entities in Asia and Europe. Recent analyses have highlighted the group's efforts to enhance its malware arsenal, targeting sensitive information within compromised systems.
In 2025, HoneyMyte expanded its malware capabilities by upgrading the CoolClient backdoor with additional functionalities. This malware is predominantly targeting Southeast Asian government agencies. It incorporates a multi-stage delivery system leveraging DLL sideloading, where legitimate software files are exploited to run malicious code.
The group's activities have been documented in countries such as Myanmar, Mongolia, Malaysia, Russia, and Pakistan. Between 2021 and 2025, HoneyMyte utilized applications from vendors like BitDefender, VLC Media Player, and Sangfor to execute its payloads.
A significant advancement in HoneyMyte's toolkit includes a browser credential stealer that targets login data stored in various web browsers. This stealer has been deployed in multiple variants:
Recent analyses have highlighted the group's efforts to enhance its malware arsenal, targeting sensitive information within compromised systems.
Variant A targets Google Chrome. Variant B focuses on Microsoft Edge. Variant C supports multiple Chromium-based browsers, including Brave and Opera.
The malware copies login databases and configuration files from targeted browsers to temporary folders, subsequently decrypting stored passwords using Windows security functions. The extracted credentials are stored in hidden folders for later exfiltration to attacker-controlled servers.
Organizations, especially in government sectors, should enhance their detection and monitoring strategies to identify signs of CoolClient backdoor infections and browser stealer activities. The evolution of HoneyMyte's tactics underscores the necessity for robust cybersecurity measures to mitigate risks associated with this threat actor.
Based on reporting by Cyber Security News.
