HoneyMyte (Mustang Panda) CoolClient Backdoor Update with Browser Data Stealers Targeting Southeast Asian Government and Military — Threadlinqs Intelligence
As of 2026-05-30, HoneyMyte (Mustang Panda) CoolClient Backdoor Update with Browser Data Stealers Targeting Southeast Asian Government and Military is a high-severity apt threat attributed to MUSTANG PANDA (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-0197 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: MUSTANG PANDA · China · ESPIONAGE
Kaspersky researchers identified three new variants of the CoolClient backdoor and three browser data stealer variants attributed to HoneyMyte (Mustang Panda/Earth Preta). The campaign targets
HoneyMyte, also tracked as Mustang Panda, Earth Preta, Bronze President, RedDelta, BASIN, and Camaro Dragon, is a China-nexus advanced persistent threat group that has been active since at least 2012. In 2025-2026, Kaspersky documented a significant expansion of the group's toolset centered around the CoolClient backdoor and new browser credential stealing capabilities.
CoolClient Backdoor Architecture:
CoolClient employs a multi-stage execution chain built on DLL sideloading. The group abuses legitimate signed executables from Sangfor (sang.exe), BitDefender (qutppy.exe), VLC Media Player (vlc.exe renamed as googleupdate.exe), and Ulead PhotoImpact (olreg.exe) to load a malicious DLL (libngs.dll). This loader decrypts and executes encrypted second-stage (loader.dat), third-stage (main.dat), and configuration (time.dat) payloads entirely in memory. The backdoor communicates over raw TCP using magic values (0xFFAABBCC for beacon/configuration, 0xFFAABBCD for operational commands) and supports in-memory plugin loading for service management (ServiceMgrS.dll), file operations (FileMgrS.dll), and remote shell access (RemoteShellS.dll).
Core Capabilities:
CoolClient provides comprehensive host surveillance including keylogging, clipboard monitoring (output stored XOR-encrypted with key 0xAC to C:\ProgramData\AppxProvisioning.xml), active window monitoring, HTTP proxy credential interception via raw TCP packet analysis extracting Base64-encoded Proxy-Authorization headers, file search and exfiltration, reverse tunnel and proxy setup, and UAC bypass through svchost.exe PEB spoofing and access token duplication from elevated processes.
Browser Data Stealers:
Three distinct browser credential stealers were deployed: Variant A targets Google Chrome Login Data and Local State files, Variant B targets Microsoft Edge, and Variant C is a generalized Chromium-based browser stealer. All variants use SQL queries against the Login Data SQLite database (SELECT origin_url, username_value, password_value FROM logins) and decrypt DPAPI-protected credentials. Stolen data is staged to C:\Users\Public\Libraries\License.txt before exfiltration.
Reconnaissance and Exfiltration Scripts:
The campaign deploys batch and PowerShell scripts for comprehensive host profiling. A batch script (1.bat) performs network mapping via nbtscan, system enumeration, registry inspection, antivirus detection, and credential dumping, with results uploaded via FTP to 113.23.212.15. PowerShell scripts (Ttraazcs32.ps1 and t.ps1) enumerate public IP, Wi-Fi networks, and recently modified documents across all drives, exfiltrating via FTP and the Pixeldrain API using hardcoded authentication tokens. Document theft targets .doc, .xls, .pdf, .tif, and .txt files modified within 60 days, compressed with RAR using the password PIXELDRAIN. Google Drive OAuth tokens are also abused for browser cookie exfiltration.
The campaign primarily targets government and military entities in Southeast Asia including Myanmar, Philippines, Vietnam, Thailand, Mongolia, Malaysia, Pakistan, and Russia. CoolClient is frequently deployed as a secondary backdoor alongside PlugX and LuminousMoth infections, suggesting operational overlap or shared infrastructure between these threat clusters.
---
**Revalidated on 2026-03-12**
Post-PlugX Tactical Pivot:
The January 2025 FBI/DOJ takedown of Mustang Panda's PlugX infrastructure (4,258 U.S. systems cleaned in coordination with French law enforcement and Sekoia.io) provides critical strategic context for this campaign. The group's 2025-2026 pivot to CoolClient as a primary implant, alongside TONESHELL and LOTUSLITE, represents a deliberate retooling response to the loss of their decade-old PlugX capability. CoolClient's in-memory execution, encrypted multi-stage payloads, and raw TCP C2 protocol demonstrate lessons learned from PlugX's detection and takedown.
Concurrent Operations (January 2026):
Simultaneously with the CoolClient browser stealer campai
Weaknesses (CWE)
CWE-426, CWE-522
Target sectors: government, military, defense, diplomatic, foreign-affairs
Target regions: Southeast Asia, Philippines, Vietnam, Myanmar, Thailand, Mongolia, Malaysia, Pakistan, Russia, East Asia, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1091, T1059, T1059, T1106, T1204, T1129, T1547, T1053, T1543