Chinese Hacking Group Hides Backdoor Behind a Signed Windows Rootkit

Kaspersky researchers say the Mustang Panda crew paired an updated CoolClient backdoor with a kernel-level cloaking tool, striking targets in Myanmar and Pakistan.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A Windows system registry editor window displayed on a monitor, with kernel-level entries highlighted in red, while a map in the background shows target regions
Share

Key points

  • Kaspersky researchers linked a new campaign to Mustang Panda, also tracked as HoneyMyte, a hacking group widely attributed to Chinese state interests.
  • The attackers deployed an updated CoolClient backdoor, a remote-control tool that lets them run commands on infected machines.
  • The backdoor is paired with a signed Windows kernel-mode rootkit that hides files, processes, registry entries and network traffic from defenders.
  • Confirmed victims sit in Myanmar, Mongolia and Pakistan, according to Kaspersky's telemetry.
  • Because the rootkit carries a valid digital signature, Windows loads it without complaint, blunting many standard detection tools.

A hacking group that Western researchers have followed for years under the names Mustang Panda and HoneyMyte has quietly upgraded its toolkit. According to Kaspersky, the group is now installing a fresh version of a backdoor called CoolClient alongside a rootkit that burrows into the deepest layer of Windows. The Hacker News first reported the finding.

Once the malware lands, the attackers can watch and steal at will, and the machine's own security software struggles to see any of it. We first covered HoneyMyte on 17 August 2026; this campaign shows the group adding meaningful technical depth to kit we'd already flagged as mature.

What did the attackers actually install?

Two things that work together. CoolClient is a backdoor, meaning a program that gives the attackers remote control of the machine. The second piece is a rootkit, a stealth tool that sits inside the Windows kernel, the most trusted part of the operating system.

Once loaded, the rootkit hides the backdoor's files so they don't appear in folder listings. Registry entries the malware needs to survive a reboot disappear from view. The network traffic the backdoor sends back to its operators, known as command-and-control or C2 traffic, is masked as well.

That combination is unusual. Kernel rootkits are difficult to write and easy to break. Most criminal crews avoid them. State-linked groups tend to be the ones with the patience.

Why does a signed driver matter?

Windows trusts it by default. The operating system requires kernel drivers to carry a valid digital signature from a recognised authority before loading them. That rule exists to keep malicious code out of the kernel.

When attackers get hold of a signed driver, whether by stealing a certificate or abusing a legitimate one, they walk straight past that gate. Antivirus tools that check signatures see a green tick and move on.

Who is being targeted?

Kaspersky found victims in Myanmar, Mongolia and Pakistan. Mustang Panda has a long history of espionage against government bodies and telecom operators across South and Southeast Asia, and the geography fits. Our 31 July story on Chinese-speaking hackers hitting Central Asian governments found a similar regional footprint from a separate crew.

The people at risk are staff inside ministries, embassies and organisations that do business with governments in the region. Home users aren't the target.

What should defenders look at?

Focus on the driver layer. Security teams can pull a list of every kernel driver loaded on their endpoints and check the signing certificate and file hash against known-good inventories. Anything signed by a revoked certificate, or issued to an obscure company, deserves a second look.

Microsoft maintains a driver block list that Windows can enforce automatically. Turning it on closes off many of the abused drivers that crews like Mustang Panda favour.

Log outbound network traffic at the firewall, not just on the endpoint. A rootkit can lie to the machine it lives on. It can't lie to the router.

Common questions

Am I personally at risk from this malware?

Probably not. This campaign targets government and policy organisations in a small number of Asian countries. Home users and most businesses outside that scope aren't in the crosshairs.

Does antivirus catch signed rootkits?

Often no, at least not on signature alone. Modern endpoint tools that watch driver behaviour rather than just checking signatures have a better chance, which is why Microsoft's driver block list and behavioural detection matter here.

© 2026 Threat Vectr