HoneyMyte arms CoolClient with a signed kernel rootkit that hides processes from security tools
Kaspersky has found a new CoolClient backdoor variant carrying a signed kernel driver that hides processes, files, registry keys, and network connections. The HoneyMyte group (Mustang Panda) is using it against governments in Asia — detecting it requires kernel-level telemetry.