Mustang Panda Deploys Signed Windows Kernel‑Mode Rootkit in CoolClient Backdoor
What Happened — The threat group Mustang Panda (aka HoneyMyte) released an updated CoolClient backdoor that now includes a Microsoft‑signed kernel‑mode rootkit. The rootkit can hide malicious processes, files, registry objects and C2 traffic, giving the actors long‑term stealth on compromised Windows hosts. Kaspersky reports victim sightings in Myanmar, Mongolia and Pakistan.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how signed drivers can be abused to bypass traditional endpoint controls – a classic failure of SOC 2 CC6.1 (System Operations) and CC6.2 (Change Management).
- Highlights the need for continuous, tamper‑evident monitoring of privileged code execution as audit evidence of effective access‑control policies.
- Directly ties to Verisq’s SOC 2 Access Controls capability, which provides automated detection of unsigned/abused drivers and immutable logs for audit trails.
Who Is Affected – Organizations with Windows‑based workloads across any sector, especially those that allow third‑party software installation or rely on legacy privileged‑access tools.
Recommended Actions
- Verify that all kernel‑mode drivers are signed by trusted authorities and enforce strict allow‑list policies.
- Deploy continuous kernel‑integrity monitoring and retain immutable logs for SOC 2 evidence.
- Conduct a rapid review of privileged‑access controls (CC6.1/CC6.2) and update incident‑response playbooks to include rootkit detection.
Source: The Hacker News
Technical Notes
- Attack vector: Malware – signed Windows kernel‑mode rootkit embedded in CoolClient backdoor.
- Capabilities: Hides processes, files, registry keys, and C2 traffic; leverages Microsoft code‑signing to evade AV.
- Observed victims: Myanmar, Mongolia, Pakistan (geographically dispersed).