HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

• HoneyMyte upgraded CoolClient backdoor with new features, enhancing persistence and stealth. • The group deployed multiple browser login data stealers across recent campaigns. •

Cybersecurity · January 27, 2026 (updated February 24, 2026) · 1 min · 177 words
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi

Cybersecurity · December 29, 2025 (updated February 24, 2026) · 2 min · 278 words