COOLCLIENT

COOLCLIENTCoolClient

Description

CoolClient is a modular backdoor used by Mustang Panda. The name is not a vendor label: it comes from the developers' own build paths, recovered by Sophos in November 2022 from PDB strings such as G:\project\木马\Cool\Client\hijack_export\libvlc\Release\libvlc.pdb, where 木马 means trojan. Sophos documented the campaign without attributing it, noting that Mustang Panda and LuminousMoth artefacts found alongside were collateral of the USB worm's indiscriminate file collection rather than evidence of collusion; Trend Micro attributed the backdoor to Mustang Panda in 2023, Symantec observed it against telecom operators in Asia in June 2024, and Kaspersky has tracked it since 2025. It is delivered by DLL sideloading through a renamed legitimate binary, persists as a service, terminates security software, and supports file read and delete, clipboard and active-window monitoring, and second-stage delivery. Kaspersky's August 2026 analysis describes a variant that installs a kernel-mode rootkit driver signed with an expired Nanjing Ranyi Technology Co., Ltd. certificate, hooking nsiproxy to hide the C2 addresses from local network tooling. Note that only Kaspersky labels samples Rootkit.Win64.CoolClient; other engines report the driver as Etset or generic rootkit detections.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.