
Findings and evidence
Kaspersky describes a newer CoolClient variant with a Windows kernel-mode component, attributed by the researchers to HoneyMyte. The analysis compares it with earlier versions and documents how the driver changes what ordinary user-mode inspection can observe.
Why it matters
When evidence sources disagree, retain both observations and document the collection layer. Correlating memory, disk and externally collected network records can help identify blind spots without assuming that one tool provides a complete view.
Scope and limits
The report analyzes particular variants. A signed driver or an incomplete process listing is not, by itself, proof of this malware family.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-08-14. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.