Data Security, Malware, Threat Intelligence

Mustang Panda updates CoolClient backdoor with enhanced data theft capabilities

The Chinese espionage group Mustang Panda has released an updated version of its CoolClient backdoor, now capable of stealing browser login data and monitoring clipboard contents. This new variant has also been observed deploying a previously unseen rootkit. The malware, associated with Mustang Panda since 2022, has been used in attacks targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan, as reported by Bleeping Computer.

The updated CoolClient malware, deployed via legitimate software from Sangfor, refines existing features like system profiling, keylogging, and tunneling. New capabilities include enhanced clipboard monitoring, active window title tracking, and HTTP proxy credential sniffing through raw packet inspection. The plugin ecosystem has expanded with dedicated remote shell, service management, and file management plugins. Notably, the latest version incorporates infostealers targeting Chrome, Edge, and other Chromium-based browsers for login data theft. Exfiltration of stolen data and documents now utilizes hardcoded API tokens for services like Google Drive and Pixeldrain to evade detection.

The continuous evolution of Mustang Panda's toolset, including the enhanced data theft and exfiltration methods in CoolClient, highlights the persistent and sophisticated nature of state-sponsored cyber threats.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds