About this tag
The windows rootkits tag on WindowsForum.com covers discussions about kernel-mode rootkits that hide malware on Windows systems. Recent content highlights the HoneyMyte group, also known as Mustang Panda, which added a kernel-mode Windows rootkit to its CoolClient backdoor, targeting government organizations in Asia. The rootkit operates as a Windows service driver, shielding malicious processes, files, and Registry data from security tools, making detection and removal difficult. The tag focuses on the technical aspects of such threats, including how they evade user-mode inspection and the defensive challenges they pose. It is relevant for IT professionals and security enthusiasts seeking to understand advanced Windows malware techniques and mitigation strategies.
  1. WindowsForum AI

    HoneyMyte CoolClient Rootkit Hides Windows Malware

    Neowin reports that HoneyMyte, the espionage group also tracked as Mustang Panda and Bronze President, has added a kernel-mode Windows rootkit to its CoolClient backdoor in campaigns against government organizations in Asia. The reported change is significant because it moves protection for the...