Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Summary
The threat actor Mustang Panda has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit. This rootkit allows the malware to hide malicious processes, files, registry objects, and C2 network information, enhancing its stealth capabilities. Victims have been identified in Myanmar, Mongolia, and Pakistan.
IFF Assessment
The introduction of a signed kernel-mode rootkit significantly increases the stealth and persistence capabilities of the CoolClient backdoor, making it harder for defenders to detect and remove.
Defender Context
Defenders should be aware of this advanced evasion technique employed by Mustang Panda. Monitoring for unusual kernel-level activity and ensuring robust endpoint detection and response (EDR) solutions are in place are crucial for mitigating the threat posed by signed rootkits.