Mustang Panda Group Deploys Signed Windows Rootkit
TL;DR. Mustang Panda, a state-backed cyberespionage group, now uses a signed Windows rootkit to enhance its CoolClient backdoor. - The rootkit, named 'Pteranodon,' helps conceal the CoolClient backdoor for stealthy operations. - This signing bypasses Windows' driver signature enforcement, making detection and removal harder. - The tactic targets Southeast Asian government entities, increasing the sophistication of attacks.
- Mustang Panda is employing a new signed Windows rootkit called 'Pteranodon'.
- This rootkit hides the 'CoolClient' backdoor, improving its stealth capabilities.
- The use of a valid digital signature allows the rootkit to bypass Windows security measures.
- The attacks primarily target government organizations in Southeast Asia.
Sources
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth — thehackernews.com