The Chinese espionage group Mustang Panda has released an updated version of its CoolClient backdoor, now capable of stealing browser login data and monitoring clipboard contents. This new variant has also been observed deploying a previously unseen rootkit. The malware, associated with Mustang Panda since 2022, has been used in attacks targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan, as reported by Bleeping Computer.The updated CoolClient malware, deployed via legitimate software from Sangfor, refines existing features like system profiling, keylogging, and tunneling. New capabilities include enhanced clipboard monitoring, active window title tracking, and HTTP proxy credential sniffing through raw packet inspection. The plugin ecosystem has expanded with dedicated remote shell, service management, and file management plugins. Notably, the latest version incorporates infostealers targeting Chrome, Edge, and other Chromium-based browsers for login data theft. Exfiltration of stolen data and documents now utilizes hardcoded API tokens for services like Google Drive and Pixeldrain to evade detection.The continuous evolution of Mustang Panda's toolset, including the enhanced data theft and exfiltration methods in CoolClient, highlights the persistent and sophisticated nature of state-sponsored cyber threats.Source: Bleeping Computer
Data Security, Malware, Threat Intelligence
Mustang Panda updates CoolClient backdoor with enhanced data theft capabilities

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



