HoneyMyte APT group has upgraded the CoolClient backdoor with a kernel-mode Windows rootkit driver (msagent.sys) that provides process hiding, file and registry protection, and network data filtering via Nsiproxy hooking. The driver is signed with an expired certificate from 2013-2014 issued to 'Nanjing Ranyi Technology Co., Ltd.' and communicates with the user-mode backdoor through IOCTL requests to device \Device\ToolTool. The malware uses DLL sideloading via a legitimate Sangfor application and a multi-stage execution chain with encrypted payloads, establishing persistence through AutoRun registry keys and Windows services.
Kernel Rootkit
2 posts
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Symantec identified renewed activity of Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit that hijacks legitimate TCP connections for covert C2, on a Taiwan manufacturing subsidiary in May 2026, four years after its initial public disclosure. Alongside it, researchers discovered a new backdoor, Stupig, which abuses the Windows keyboard-layout provider mechanism to execute SYSTEM-level commands from the logon screen pre-authentication and hook credential-handling APIs within winlogon.exe. Compile timestamps on both tools date to 2013 despite the host having no telemetry until 2026, suggesting a potentially decade-plus dwell time enabled by likely initial access via an outdated, end-of-life Digiwin SSO/JDK deployment.