Dangerous Malware is Targeting Govt and Organizations in Pakistan

Kaspersky Global Research and Analysis Team (GReAT) has identified an updated version of the CoolClient backdoor being applied in a 2026 cyber-espionage campaign targeting organizations and administration entities in Myanmar, Mongolia, Pakistan, India, and Russia.

TechnologyNews Info Wire3 min read
Dangerous Malware is Targeting Govt and Organizations in Pakistan

Kaspersky Global Research and Analysis Team (GReAT) has identified an updated version of the CoolClient backdoor being applied in a 2026 cyber-espionage campaign targeting organizations and administration entities in Myanmar, Mongolia, Pakistan, India, and Russia.

Article outline

  1. What happened
  2. The key numbers
  3. Background
  4. Why it matters
  5. The details
  6. The bottom line

Key points

  • AI Agents Aren't Just Deceiving Humans – They're Now Hacking Each Other.
  • Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.
  • Kaspersky Security Researcher Fareed Radzi remarked the new CoolClient variant can hide and protect processes, files, and registry objects while additionally filtering selected network information.
  • OpenAI Launches GPT-5.6 Cyber as AI Hacking Threats Grow.
  • The malware has been linked to HoneyMyte, additionally known as Mustang Panda, and provides attackers with remote access to compromised Windows systems.

Notably, the malware has been linked to HoneyMyte, additionally known as Mustang Panda, and provides attackers with remote access to compromised Windows systems.

As it uses a signed kernel driver to operate deep within Windows systems and create detection and removal more challenging, according to Kaspersky, the latest CoolClient variant represents a significant evolution of the malware.

In the observed campaign, attackers applied PlugX, another backdoor commonly deployed after an initial compromise, to deliver CoolClient components to targeted systems.

In practice, the attackers additionally configured Microsoft Defender to exclude a specific folder and file from scanning. While a legitimate Sangfor program was renamed "defender.exe" to support load malicious code, a fake Windows Defender directory was created, and CoolClient files were placed inside it.

Meanwhile, the attackers subsequently created a scheduled task to automatically launch the renamed executable at system startup with the highest local Windows privileges.

He remarked the kernel-mode driver extends the malware's capabilities beyond earlier versions, allowing it to remain active on compromised systems while masking notable traces and restricting defenders' ability to inspect or remove it. OpenAI Launches GPT-5.6 Cyber as AI Hacking Threats Grow.

Kaspersky GReAT has advised organizations to remain vigilant against HoneyMyte indicators of compromise and related tools identified in the campaign.

While additionally using threat intelligence to identify risks at an early stage, the firm recommended strengthening real-time protection, threat visibility, investigation and response capabilities.

Organizations lacking in-house cybersecurity expertise were advised to consider managed security services covering threat identification, detection, response and remediation.

Obtain the latest tech news, telecom insights, and product launches wherever you prefer.

Add as a preferredSource on Google Follow on Google News Join WhatsApp.

In short, dangerous Malware is Targeting Govt and Organizations in Pakistan is the central thread here, and readers can expect follow-up reporting as the picture becomes clearer.

Leave a Reply

Your email address will not be published. Required fields are marked *