{"id":10200,"date":"2026-01-28T10:03:35","date_gmt":"2026-01-28T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/28\/honeymyte-hacker-group-updates-coolclient-malware-to-deploy-browser-login-data-stealer\/"},"modified":"2026-01-28T10:03:35","modified_gmt":"2026-01-28T10:03:35","slug":"honeymyte-hacker-group-updates-coolclient-malware-to-deploy-browser-login-data-stealer","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/28\/honeymyte-hacker-group-updates-coolclient-malware-to-deploy-browser-login-data-stealer\/","title":{"rendered":"HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer"},"content":{"rendered":"<p>    HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. <\/p>\n<p>Recent security research has revealed that this advanced hacker collective is actively upgrading its digital arsenal with enhanced versions of malware designed to steal sensitive information from targeted systems. <\/p>\n<p>The group\u2019s operations have been particularly concentrated in Southeast Asia, where government agencies remain the primary targets of their sophisticated campaigns.<\/p>\n<p>In 2025, security experts discovered that HoneyMyte significantly expanded its toolset by improving the CoolClient backdoor <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> with new capabilities. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6pl5PMC_nUsKxneN3DFGxvGFdmOYcaYXNCTjwmFWlv4NOd8_KQZRf-azxUkJfG_xFhYPAsD1XRclejvtayn3m2weBeEdrDQCQj_z2U1gt8u0g1mFlIXS2tVYkzkN26k1aVm2E9ZMd23XSgRD0CxsCpGm5OWkIsiBaNe8VEpZ6ilV364fVGcmdRU-P1vY\/s16000\/Variants%2520of%2520CoolClient%2520abusing%2520different%2520software%2520for%2520DLL%2520sideloading%2520%282021%25E2%2580%25932025%29%2520%28Source%2520-%2520Securelist%29.webp?ssl=1\" alt=\"Variants of CoolClient abusing different software for DLL sideloading (2021\u20132025) (Source - Securelist)\"><figcaption class=\"wp-element-caption\">Variants of CoolClient abusing different software for DLL sideloading (2021\u20132025) (Source \u2013 Securelist)<\/figcaption><\/figure>\n<\/div>\n<p>Beyond the CoolClient upgrades, the group deployed several variants of a specialized browser login data stealer and utilized multiple scripts intended for harvesting confidential documents and gathering system details. <\/p>\n<p>This evolution demonstrates the group\u2019s commitment to developing more effective tools for extracting valuable <a href=\"https:\/\/cybersecuritynews.com\/russian-hacker-sentenced-for-data-theft-of-linkedin-dropbox-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">data<\/a> from compromised networks.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgOs7CvSuGUQAAKygGJ-EAZW6deQr8H5-TwtuY-pKryAXAMlCihZ5NsXa7Mp4VtpTpy2MRd0-tUA3S6jnNU6ESl1JFSiE0pdB7I6vK1YYRllMunH5r2gaIKqeQKWhXjPOs8QqfEqgYAfsyfyoVv5CDKsxvQ7AB4keTM2dzPWE_rbsfsRUfvL7Vh3zZwuDU\/s16000\/Overview%2520of%2520CoolClient%2520execution%2520flow%2520%28Source%2520-%2520Securelist%29.webp?ssl=1\" alt=\"Overview of CoolClient execution flow (Source - Securelist)\"><figcaption class=\"wp-element-caption\">Overview of CoolClient execution flow (Source \u2013 Securelist)<\/figcaption><\/figure>\n<\/div>\n<p>Securelist analysts <a href=\"https:\/\/securelist.com\/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts\/118664\/\" target=\"_blank\" rel=\"noreferrer noopener\">noted<\/a> that the malware operates through a multi-stage delivery system that relies on DLL sideloading, a technique where legitimate software files are hijacked to load malicious code. <\/p>\n<p>The malware has been observed in countries including Myanmar, Mongolia, Malaysia, Russia, and Pakistan. <\/p>\n<p>Between 2021 and 2025, HoneyMyte abused legitimate applications from vendors such as BitDefender, VLC Media Player, and Sangfor to execute its malicious payload.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-browser-credential-stealer-and-detection-evasion\"><strong>The Browser Credential Stealer and Detection Evasion<\/strong><\/h2>\n<p>One of the most concerning developments involves HoneyMyte\u2019s new browser credential stealer, which specifically targets login information stored in popular web browsers. <\/p>\n<p>The group deployed at least three variants of this stealer across different campaigns. Variant A targets Google Chrome, Variant B focuses on Microsoft Edge, and Variant C supports multiple Chromium-based browsers including Brave and Opera.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiSBWCEbXIkI6-wQQmaPIrhvw-CX7X_24KFRduParuWY9m7mArUNojyMbWgcaaTGTajy7OMvJfKhNx1ANOZLGf6Bpv5bCPkohRs_MzLXpVQPJUqWW_46DLwazbadEcvb0wBn3kOkqfMRtpAMXYb0xBbDDoPGRCRrDMFWxM73EXd_sS1U6zlnSoZ-OfXRsw\/s16000\/Function%2520that%2520copies%2520Chrome%2520browser%2520login%2520data%2520into%2520a%2520temporary%2520file%2520%28chromeTmp%29%2520for%2520exfiltration%2520%28Source%2520-%2520Securelist%29.webp?ssl=1\" alt=\"Function that copies Chrome browser login data into a temporary file (chromeTmp) for exfiltration (Source - Securelist) \"><figcaption class=\"wp-element-caption\">Function that copies Chrome browser login data into a temporary file (chromeTmp) for exfiltration (Source \u2013 Securelist) <\/figcaption><\/figure>\n<\/div>\n<p>This flexibility allows attackers to <a href=\"https:\/\/cybersecuritynews.com\/researchers-detailed-letmeowin-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">harvest credentials<\/a> regardless of which browser users prefer on compromised machines.<\/p>\n<p>The stealer operates by copying the target browser\u2019s login database and configuration files to temporary folders, then using Windows security features to decrypt stored passwords. <\/p>\n<p>The malware extracts encrypted master keys from browser files, decrypts them using Windows Data Protection Application Programming Interface functions, and reconstructs complete login records containing usernames and passwords. <\/p>\n<p>After gathering this sensitive information, the malware saves the harvested credentials to hidden system folders for later exfiltration to attacker-controlled servers.<\/p>\n<p>This capability, combined with other features like <a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-using-malicious-scripts-combining-beavertail-and-ottercookie-for-keylogging\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogging<\/a> and clipboard monitoring, reveals HoneyMyte\u2019s transition toward active surveillance of victim systems beyond traditional espionage objectives. <\/p>\n<p>Organizations operating in government sectors should implement strong detection measures and maintain vigilant monitoring for signs of CoolClient backdoor infections, browser stealer activity, and related malware families used by this determined threat actor.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/honeymyte-hacker-group-updates-coolclient-malware\/\">HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/honeymyte-hacker-group-updates-coolclient-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. Recent security research has revealed that this advanced hacker collective is actively upgrading its digital arsenal with enhanced [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10200","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10200"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10200"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10200\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10200"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}