BusinessTechnologyTurkiye

HoneyMyte APT Expands Cyber Espionage Campaigns Targeting Government Institutions

Kaspersky’s Global Research and Analysis Team (GReAT) has identified an expansion in cyber espionage campaigns conducted by the HoneyMyte advanced persistent threat (APT) group, revealing the use of enhanced surveillance capabilities and an expanded malware toolkit targeting government institutions.

According to Kaspersky, HoneyMyte has upgraded its CoolClient backdoor with new functionalities and deployed additional data-stealing scripts aimed at reconnaissance and data exfiltration. The group is also using multiple browser-focused malware tools to steal sensitive information.

The latest campaigns, attributed to the state-sponsored APT group, have targeted organizations in Myanmar, Mongolia, Malaysia, Thailand, and Russia, with a particular focus on public sector entities.

Advanced Malware Distribution Techniques

Kaspersky researchers found that the latest version of the CoolClient backdoor is primarily distributed as a secondary backdoor alongside PlugX and LuminousMoth malware families. The malware employs a DLL side-loading technique, abusing legitimate, digitally signed applications to load malicious DLL files.

Experts noted that HoneyMyte exploited signed files from various software vendors between 2021 and 2025, while recent campaigns have leveraged a digitally signed application from Sangfor.

New Surveillance Capabilities Identified

Newly added features to CoolClient include clipboard monitoring and active window tracking, enabling attackers to capture copied data along with window titles, process IDs, and timestamps. These enhancements allow for detailed monitoring of user activity.

The backdoor has also gained the ability to intercept HTTP proxy credentials from network traffic—an ability observed for the first time within the HoneyMyte toolset. The identification of numerous active plugins further highlights the malware’s modular and extensible architecture.

Credential Theft and Data Exfiltration

In some espionage operations, HoneyMyte uses scripts to collect system information, exfiltrate documents, and steal credentials stored in web browsers. During post-exploitation phases, attackers deploy a new malware variant targeting Google Chrome credentials.

Kaspersky researchers observed that this malware shares a high degree of code similarity with samples previously used in ToneShell campaigns.

Security Recommendations

Kaspersky advised organizations to increase awareness of HoneyMyte and similar APT threats, deploy advanced security solutions offering EDR and XDR capabilities, adopt managed detection and response (MDR) services, and strengthen incident response processes through enhanced threat intelligence integration.

Fareed Radzi, a security researcher at Kaspersky GReAT, stated that active surveillance techniques—such as keylogging, clipboard monitoring, proxy credential theft, document exfiltration, browser credential harvesting, and large-scale file theft—have become standard tactics for APT groups.

“This evolution requires a level of preparedness and proactive defense that is just as strong as traditional countermeasures against data exfiltration and persistence mechanisms,” Radzi said.

Source: Anadolu Ajansı/ Prepared by: İlayda Gök

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button