CoolClient Backdoor created by threat actor group Mustang Panda
Mustang Panda, aka HoneyMyte, is a threat actor that has recently deployed a version of the CoolClient backdoor with a Windows rootkit that protects malicious processes and other backdoors. The kernel is deployed when CoolClient has full access to the Service Control Manager and other privileges, and if it doesn't the malware goes straight to final level implants. Keylogging, client theft, credential harvesting, and other malicious processes are supported by CoolClient. Several hashes have been listed by Russian security provider Kaspersky as indicators and can be used to avoid the backdoor.