HoneyMyte strengthens malware to infiltrate company systems

Researchers report HoneyMyte’s malware now monitors clipboard, apps, and network credentials silently inside corporate networks.

 


What if someone could watch every click you make at work… without you noticing?

A new cyber-espionage campaign reveals how attackers no longer break in—they install and observe.


Digital espionage no longer forces its way in: it sits, watches, and learns. This is the unsettling reality behind new cyber-espionage campaigns detected by Kaspersky, in which an advanced persistent threat (APT) group known as HoneyMyte has refined its tools to monitor daily user activity within corporate networks without raising suspicion.

The company revealed that the group has strengthened its primary malicious tool, CoolClient, expanding its capabilities to monitor user behavior in compromised systems with greater precision. The campaigns target especially government entities and strategic organizations, where the information handled is highly sensitive.

Invisible Monitoring.

According to researchers from Kaspersky’s Global Research and Analysis Team (GReAT), CoolClient can now monitor the clipboard and track the applications in use, enabling the collection of data such as active window titles, associated processes, and timestamps of each activity.

With this information, attackers can accurately reconstruct the operational context in which employees handle sensitive data.

Another detected capability is the theft of network proxy credentials, critical information used to control internet access in companies and organizations. This technique, previously unseen in HoneyMyte malware, significantly expands the group’s ability to move stealthily within corporate networks.

Legitimate Tools.

Research also indicates that CoolClient is often installed as a backdoor, alongside other malware variants such as PlugX and LuminousMoth.

To execute the attacks, the group exploits a method using legitimate, digitally signed files, making detection by traditional security solutions more difficult. Between 2021 and 2025, HoneyMyte abused genuine programs from various vendors, and in more recent campaigns, it used a signed application from an enterprise software provider.

In parallel, the attackers employed automated scripts to collect system information, extract internal documents, and steal credentials stored in web browsers. In the post-attack phase, experts also identified a new version of specialized malware designed to steal Google Chrome passwords, with technical similarities to tools used in previous espionage campaigns.

Prolonged Espionage.

This type of attack represents a significant risk to organizations because it does not aim to cause an immediate or visible impact, but rather to remain hidden for extended periods. By operating with legitimate tools and silent techniques, attackers can observe work habits, gather strategic information, and progressively extract data, acting from within as if they were authorized users.

Leandro Cuozzo, Security Analyst at Kaspersky’s Global Research and Analysis Team for Latin America, warns about this threat:

“The most concerning aspect of these campaigns is not just the technical side, but also the shift in how espionage is conducted. We are seeing attacks designed to silently observe how people work within an organization: which applications they use, what information they copy, which credentials they handle, and how they move within the network. This turns employees and their digital habits into a constant source of intelligence for attackers. For companies, the risk is no longer limited to a single data leak but extends to the gradual loss of strategic information, credentials, and operational context, often without clear signs of intrusion.”

Against this backdrop, experts recommend that organizations maintain constant vigilance for signs of digital espionage, such as unusual device behavior, unexpected access to sensitive information, atypical use of legitimate programs, or data movements that do not align with normal tasks.

They also suggest verifying which authorized programs and files are allowed to run, as many advanced attacks enter via legitimate software that should not be active on systems.

Additionally, it is crucial to have detection tools capable of identifying anomalous activity in real time and responding before critical information is compromised.

Support from managed security services, such as managed detection and response or incident response, can be key to investigating complex attacks and containing threats promptly, especially in organizations with limited resources.

Finally, leveraging threat intelligence helps strengthen decision-making by providing context on active risks and anticipating scenarios before they escalate into major incidents.


Share:
Hosting Web
Most Read