The HoneyMyte, also known internationally as Mustang Panda or Bronze President, continues to be one of the most active and dangerous threats to government organizations in Asia and Europe. New findings by cybersecurity researchers show that the group not only remains active, but is also systematically investing in upgrading its tools .

It is an advanced persistent threat (APT), with a long-standing presence in the cyber espionage arena and an operational maturity that differentiates it from simple criminal groups.
Target Southeast Asia – but not only
HoneyMyte's most recent attacks are focused primarily on Southeast Asia, where government agencies, diplomatic networks, and defense organizations are key targets.
See also: Expansion of ClickFix attacks using fake CAPTCHAs
However, analysts confirm the presence of the malware in other countries, such as:
- Myanmar
- Mongolia
- Malaysia
- Russia
- Pakistan
This geographical spread proves that the group's operations are not limited to a local level, but are part of broader espionage strategies.
CoolClient returns upgraded
A central element of the recent activity is the upgrade of the well-known CoolClient, which HoneyMyte has been using for years for long-term access to compromised systems.
The 2025 versions feature new features such as:
- improved process hiding
- more stable communication with command-and-control servers
- enhanced system information collection
The ongoing development of CoolClient shows that the team does not rely on off-the-shelf tools, but maintains an active internal malware development.

Multi-stage attacks with DLL sideloading
According to Securelist researchers , recent campaigns rely on a multi-stage delivery mechanism , with DLL sideloading as a key technique .
This method allows attackers to:
- use legitimate applications
- load malicious libraries
- bypass antivirus and EDR
Between 2021 and 2025, HoneyMyte has abused software from well-known vendors such as BitDefender, VLC Media Player, and Sangfor.
The use of trusted files makes detecting the attack extremely difficult.
See also: 6,000 SmarterMail servers exposed to the internet and vulnerable to attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
New browser credential thief
Of particular concern is the emergence of a specialized credential stealer browser, which represents a significant upgrade to the group's espionage capabilities.
Analysts identified at least three distinct variants:
- Variant A: target Google Chrome
- Variant B: attack on Microsoft Edge
- Variant C: support for multiple Chromium browsers such as Brave and Opera
This flexibility allows attackers to extract data regardless of user preferences.

How passwords are intercepted
The malware copies browser connection databases to temporary folders and exploits legitimate Windows functions for decryption.
Specifically, it extracts the encrypted master keys, decrypts them via Windows DPAPI , and reconstructs complete files with usernames and passwords. The data is temporarily stored in hidden folders until it is extracted to the attackers' servers.
In addition to credential theft, the new versions support keystroke logging, clipboard monitoring, and document collection.
This marks a transition from passive cyberespionage to constant surveillance of victims' systems.
See also: SoundCloud: Data breach affects 29.8 million accounts

What should organizations do?
Government and public bodies are called upon to immediately strengthen:
- DLL sideloading detection mechanisms
- checking for unusual browser activity
- monitoring for CoolClient type backdoors
HoneyMyte proves that modern threats are not based on the quantity of attacks, but on persistence, “silent” operation and continuous technological evolution.
In a digital world where borders do not exist, cybersecurity now remains a matter of national strategy — not just technical defense.
