# New Chinese-Linked Rootkit Operation Exposes State-Level Cyber Reach Into Government Networks

*Friday, August 14, 2026 at 2:08 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-08-14T14:08:41.946Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/14380.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: A Mustang Panda–linked backdoor dubbed CoolClient is now hiding at the Windows kernel level using a signed rootkit, giving attackers deep, stealthy access to systems in Myanmar, Mongolia, Pakistan and Russia. The campaign shows how state-backed groups are pushing below the operating system line to quietly burrow into government networks.

A Chinese-linked hacking group has quietly crossed another line in the cyber arms race, deploying a signed Windows rootkit to hide its presence at the kernel level on government and other sensitive systems. The campaign, tied to the long-active Mustang Panda cluster, offers a stark look at how far state-backed operators are willing to go to evade detection and retain access inside foreign networks. Researchers tracking the operation report that the group is using a backdoor known as CoolClient, now cloaked by a rootkit that carries a valid digital signature. That signed component allows the malware to run deep in the Windows kernel, where it can hide its own processes,…

---

*Full article available with Hamer Intel Pro — https://hamerintel.com/pricing*
