The APT group HoneyMyte has updated its CoolClient backdoor with a kernel-level Windows rootkit to make detection harder. Here's what admins can do.

The APT group HoneyMyte has updated its CoolClient backdoor with a kernel-level Windows rootkit to make detection harder. Here's what admins can do.

HoneyMyte deploys an updated CoolClient backdoor with a signed Windows rootkit that hides malicious processes, files, registry objects, and C2 data.