SECURITY Signal 61
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
elseif has not written about this yet · Securelist describes it this way
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
THE CLUSTER
Same story, 1 feed.
Securelist
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Open ↗
↗