2026-08-15NOTABLEKaspersky documents a previously undocumented CoolClient rootkit driver, deployed only once the implant already holds SCM access and SeTcbPrivilege
Havencode
malware · malware:havencode single-source
Backdoor first observed by IBM X-Force in ITG27 (Mustang Panda-overlapping) activity, centred on hidden Virtual Network Computing so an operator can connect to and browse an infected desktop covertly. Delivered as a 64-bit DLL side-loaded by a legitimate signed executable, it supports a hidden-desktop VNC server on a supplied local port, a view-only mode attached to the user's existing desktop, and a generic TCP/UDP tunnel used to relay the local VNC server's traffic to the operator. It embeds no command-and-control address at all; the C2 is supplied as a command-line argument at execution time, so no infrastructure can be extracted from the binary statically (IBM X-Force, 2026-08-20).
Coverage
1
first 2026-08-15 → last 2026-08-21
Latest activity
2026-08-21
Kaspersky documents a previously undocumented CoolClient rootkit driver, deployed only once the implant…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, energy · regions: apac
Sources cited
3
3 hosts
Defender insights
What each entry about Havencode tells a defender to do, newest first.
Latest update · triage
Story timeline
ATT&CK techniques (18 across 8 tactics)
18 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing: Spearphishing Attachment
- ExecutionHijack Execution Flow: DLL
- PersistenceModify Registry · Create or Modify System Process: Windows Service
- Privilege EscalationProcess Injection · Create or Modify System Process: Windows Service · Abuse Elevation Control Mechanism: Bypass User Account Control
- StealthRootkit · Obfuscated Files or Information · Masquerading: Match Legitimate Resource Name or Location · Process Injection · Hijack Execution Flow: DLL
- Defense ImpairmentModify Registry · Subvert Trust Controls: Code Signing · Disable or Modify Tools
- DiscoverySystem Owner/User Discovery · System Network Connections Discovery · System Information Discovery
- Command and ControlApplication Layer Protocol: Web Protocols · Proxy · Ingress Tool Transfer · Remote Access Tools
Initial Access TA0001
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Execution TA0002
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Persistence TA0003
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Privilege Escalation TA0004
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×1
Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Stealth TA0005
T1014Rootkit×1
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1553.002Subvert Trust Controls: Code Signing×1
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Discovery TA0007
T1033System Owner/User Discovery×1
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1049System Network Connections Discovery×1
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗
Entries about Havencode (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- ibm.com1 (33%)
- securelist.com1 (33%)
- thehackernews.com1 (33%)