PULSE NAME
CoolClient backdoor updated, new data stealing tools used
WHITE MUSTANG PANDA AlienVault 2026-01-27 Modified: 2026-02-26
19
IOCs
MEDIUM VOLUME
The HoneyMyte APT group has enhanced its toolset with an updated CoolClient backdoor and new data stealing capabilities. The group targeted government entities in Asia and Europe, particularly Southeast Asia. CoolClient now features clipboard monitoring, HTTP proxy credential sniffing, and plugin support for extended functionality. HoneyMyte also deployed browser login data stealers and document theft scripts. The campaign's focus has shifted towards active surveillance, including keylogging, clipboard data collection, and proxy credential harvesting. Organizations are advised to remain vigilant against HoneyMyte's evolving toolkit, which includes CoolClient, PlugX, ToneShell, Qreverse, and LuminousMoth malware families.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
CoolClient ToneShell PlugX - S0013 Thoper TVT DestroyRAT Sogu Kaba Korplug LuminousMoth QReverse
Indicators of Compromise (1 / 19 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 78cee623d06696ee31b25aa4e1b07c5724b1f7b7 2026-01-27