counterfeit

Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
Tech Optimizer
August 8, 2026
Securonix Threat Research has identified a cyber campaign called SMOKE#SCREEN that uses deceptive tactics to trick users into installing weaponized versions of ScreenConnect, a legitimate remote monitoring software. The attackers disguise their malicious intent with fake update notifications for applications like Zoom and Adobe, as well as counterfeit business documents. This campaign allows attackers to gain persistent remote access to victims' systems, disable security protections, and exploit trusted services like Dropbox and Cloudflare for delivering malicious payloads. Victims have been reported on both Windows and macOS platforms. Businesses are advised to verify updates through official channels and train staff on the risks of unexpected software installations.
Winsage
July 30, 2026
The Microsoft Store now offers Malwarebytes for Windows, providing a convenient and reliable way for users to download the full version of the software without limitations. This version includes all features, such as real-time protection and seamless integration with Windows. Users can install it by searching for Malwarebytes in the Microsoft Store and clicking "Get." The listing also provides app information and screenshots. Existing users of Malwarebytes from the official website do not need to reinstall or make changes to their current setup.
Winsage
July 29, 2026
Microsoft is requiring the use of TPM 2.0 security modules for Key Management Service (KMS) activation servers to combat unlicensed software and corporate piracy. KMS, used by organizations for mass activation of devices, has been targeted by hackers who create counterfeit servers. The new protocol mandates that KMS hosts validate their hardware credentials through the TPM 2.0 chip before activating client devices. This initiative will mainly affect illegal infrastructures in the corporate sector, while legitimate PC users will not be impacted. Starting in August 2026, Windows Server 2025 will introduce hardware readiness alerts to help system administrators prepare for these changes. TPM 2.0 has been required for Windows 11 since 2021, and its application is being expanded to address vulnerabilities in volume licensing.
Search