{"id":207381,"date":"2026-01-28T06:40:00","date_gmt":"2026-01-28T11:40:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/01\/28\/mustang-panda-deploys-updated-coolclient-backdoor-in-government-cyber-attacks\/"},"modified":"2026-01-28T10:40:14","modified_gmt":"2026-01-28T15:40:14","slug":"mustang-panda-deploys-updated-coolclient-backdoor-in-government-cyber-attacks","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/01\/28\/mustang-panda-deploys-updated-coolclient-backdoor-in-government-cyber-attacks\/","title":{"rendered":"Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/mustang-panda-deploys-updated.html\">Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/mustang-panda-deploys-updated.html\">https:\/\/thehackernews.com\/2026\/01\/mustang-panda-deploys-updated.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-28 06:40:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>Threat actors with ties to China have been observed using an updated version of a backdoor called COOLCLIENT in cyber espionage attacks in 2025 to facilitate comprehensive data theft from infected endpoints.<\/p>\n<p>The activity has been attributed to <strong>Mustang Panda<\/strong> (aka Earth Preta, Fireant, HoneyMyte, Polaris, and Twill Typhoon) with the intrusions primarily directed against government entities located across campaigns across Myanmar, Mongolia, Malaysia, and Russia.<\/p>\n<p>Kaspersky, which disclosed details of the updated malware, said it&#8217;s deployed as a secondary backdoor along with PlugX and LuminousMoth infections.<\/p>\n<p>&#8220;COOLCLIENT was typically delivered alongside encrypted loader files containing encrypted configuration data, shellcode, and in-memory next-stage DLL modules,&#8221; the Russian cybersecurity company said. &#8220;These modules relied on DLL side-loading as their primary execution method, which required a legitimate signed executable to load a malicious DLL.&#8221;<\/p>\n<p><img decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqlhh16hjmE7NRyQeAR2_sLZ1uDwyQH2jkPHmDTAtveTHoIjCrfmK6JLqlZuNKOPG1RGLtwJk-ZJDwQiV-McwmzAUu1iOSwwMjs_tqI1KjcL_tCvc0M2XuKBPfJ1RXpKxnx-eGdWwM0wlNDnUYHvXr-1LZk2zRmDNLIEbYGalGQJsd6QwC0pyCrLavN0fz\/s728-e100\/threatlocker-inside-d.png\" width=\"729\" height=\"91\"\/><\/p>\n<p>Between 2021 and 2025, Mustang Panda is said to have leveraged signed binaries from various software products, including Bitdefender (&#8220;qutppy.exe&#8221;), VLC Media Player (&#8220;vlc.exe&#8221; renamed as &#8220;googleupdate.exe&#8221;), Ulead PhotoImpact (&#8220;olreg.exe&#8221;), and Sangfor (&#8220;sang.exe&#8221;) for this purpose.<\/p>\n<p>Campaigns observed in 2024 and 2025 have been found to abuse legitimate software developed by Sangfor, with one such wave targeting Pakistan and Myanmar using it to deliver a COOLCLIENT variant that drops and executes a previously unseen rootkit.<\/p>\n<p>COOLCLIENT was first documented by Sophos in November 2022 in a report detailing the widespread use of DLL side-loading by China-based APT groups. A subsequent analysis from Trend Micro officially attributed the backdoor to Mustang Panda and highlighted its ability to read\/delete files, as well as monitor the clipboard and active windows.<\/p>\n<p>The malware has also been put to use in attacks targeting multiple telecom operators in a single Asian country in a long-running espionage campaign that may&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/mustang-panda-deploys-updated.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks https:\/\/thehackernews.com\/2026\/01\/mustang-panda-deploys-updated.html Publish Date: 2026-01-28 06:40:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":207382,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjbfyqOKlboKyz0aepCrCjmgfx7hVJKbZ5zcv_iQC6sUvz4vyarawc69b_BxxUdQYhl62-gOoWmlEDQywKqX4zRtKo7X_G_eZTCignSldlMeGxb6ZxhYRJTFn2L0f_FcdJS2FrlLq32HpdE1N_XqD639QIYNC9xGZymr8PNBLW_mU7uB6Oa4f759T_4t-0E\/s1700-e365\/cyber.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32],"class_list":["post-207381","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207381"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=207381"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207381\/revisions"}],"predecessor-version":[{"id":207383,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207381\/revisions\/207383"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/207382"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=207381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=207381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=207381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}