Mustang Panda가 서명된 윈도우 루트킷으로 CoolClient 백도어를 업데이트했습니다.
위험 요소로 알려진 HoneyMyte가 서명된 윈도우 커널 모드 루트킷이 포함된 CoolClient 백도어의 업그레이드 버전을 배포했습니다. 이 루트킷은 악성 프로세스, 파일, 레지스트리 객체 및 명령 및 제어(C2) 네트워크 정보를 숨기고 보호하는 기능을 가지고 있습니다. Kaspersky는 미얀마, 몽골, 파키스탄에서 피해자를 확인했다고 보고했습니다.
Mustang Panda has updated the CoolClient backdoor with a signed Windows rootkit.
The threat actor known as HoneyMyte has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit. This rootkit can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Kaspersky identified victims in Myanmar, Mongolia, and Pakistan.