Mustang Panda Group Deploys Signed Windows Rootkit

TL;DR. Mustang Panda, a state-backed cyberespionage group, now uses a signed Windows rootkit to enhance its CoolClient backdoor. - The rootkit, named 'Pteranodon,' helps conceal the CoolClient backdoor for stealthy operations. - This signing bypasses Windows' driver signature enforcement, making detection and removal harder. - The tactic targets Southeast Asian government entities, increasing the sophistication of attacks.

Sources

Back to QLANKR News