This page was machine-translated and may differ from the original. View original
Honeymite APT targets government agencies, evolving information theft techniques.
CoolClient backdoor functionality expanded… DLL sideloading-based attacks confirmed in Asia and Russia.
APT attacks targeting government and diplomatic agencies are evolving into a form that combines surveillance and exfiltration capabilities. The security industry believes that with the rise in infiltrations exploiting legitimate programs and attacks involving account and document theft, proactive detection and response systems at the organizational level are becoming increasingly crucial.
Kaspersky announced on February 4, 2026 that its Global Research and Analysis Team (GReAT) has confirmed that the HoneyMyte APT has strengthened its information theft capabilities.
According to the researchers, HoneyMite is an attack group known for targeting sensitive political and strategic information from Southeast Asian governments and diplomatic organizations. In their latest campaign, they primarily targeted government sectors in Myanmar, Mongolia, Malaysia, Thailand, and Russia. During this campaign, they added new features to the CoolClient backdoor, along with a variant of a browser login data stealer and scripts for reconnaissance and exfiltration.
The core of the attack method is DLL sideloading (a technique that forces a legitimate executable file to load a malicious DLL). Kaspersky explains that threat actors have been exploiting signed binaries included in various legitimate software between 2021 and 2025, with recent campaigns utilizing signed applications from Sangfor. Additionally, the latest version of CoolClient has also been observed being distributed as a secondary backdoor along with PlugX and LuminousMoth, he added.
Technically, clipboard monitoring and active window tracking functions have been added, allowing the collection of not only clipboard contents but also the window title, process ID, and timestamp of the active application. The ability to extract HTTP proxy credentials from network traffic has also been confirmed, which is a newly observed technique in the HoneyMyte family of malware. The researchers also said that they confirmed multiple CoolClient plugins in use, revealing a custom plugin-based functional extension structure. In the post-compromise phase, a new Chrome credential stealing malware was used, and code similarities with samples from the ToneShell campaign were observed.
Kaspersky GReAT security researcher Farid Raj said active surveillance, including keylogging, clipboard monitoring, proxy credential theft, document exfiltration, browser credential harvesting, and large-scale file theft, has become standard APT tactics, requiring the same level of preparedness and preemptive defense as traditional threats. Lee Hyo-eun, head of Kaspersky Korea, noted that the threat landscape in Korea is also becoming more complex as attack methods evolve, necessitating the establishment of a comprehensive and preemptive defense system.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













