New Chinese-Linked Rootkit Operation Exposes State-Level Cyber Reach Into Government Networks
A Mustang Panda–linked backdoor dubbed CoolClient is now hiding at the Windows kernel level using a signed rootkit, giving attackers deep, stealthy access to systems in Myanmar, Mongolia, Pakistan and Russia. The campaign shows how state-backed groups are pushing below the operating system line to quietly burrow into government networks.
A Chinese-linked hacking group has quietly crossed another line in the cyber arms race, deploying a signed Windows rootkit to hide its presence at the kernel level on government and other sensitive systems. The campaign, tied to the long-active Mustang Panda cluster, offers a stark look at how far state-backed operators are willing to go to evade detection and retain access inside foreign networks. Researchers tracking the operation report that the group is using a backdoor known as CoolClient, now cloaked by a rootkit that carries a valid digital signature. That signed component allows the malware to run deep in the Windows kernel, where it can hide its own processes,…
Pro features include
- 60+ analytical tools across markets and intelligence
- Custom alerts, watchlists, and AOI monitoring
- Daily Pro brief at 6 PM ET — 12 hours before free tier
- Conflict deep dives and premium research products