← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

CoolClient research highlights the limits of a single endpoint view

Kaspersky describes a newer CoolClient variant with a Windows kernel-mode component, attributed by the researchers to HoneyMyte.

Source published 2026-08-14Malware analysisResearch briefing
Original publication preview: CoolClient research highlights the limits of a single endpoint view
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky describes a newer CoolClient variant with a Windows kernel-mode component, attributed by the researchers to HoneyMyte. The analysis compares it with earlier versions and documents how the driver changes what ordinary user-mode inspection can observe.

Why it matters

When evidence sources disagree, retain both observations and document the collection layer. Correlating memory, disk and externally collected network records can help identify blind spots without assuming that one tool provides a complete view.

Scope and limits

The report analyzes particular variants. A signed driver or an incomplete process listing is not, by itself, proof of this malware family.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-08-14. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC