Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

An new version of the backdoor TONESHELL and a hitherto unreported USB worm dubbed SnakeDisk have been seen being used by the China-aligned threat actor Mustang Panda.

In an investigation released last week, IBM X-Force experts Golo Mühr and Joshua Chung stated that the worm only runs on machines with IP addresses based in Thailand and opens the Yokai backdoor.

Hive0154, also known as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, Polaris, RedDelta, Stately Taurus, and Twill Typhoon, is the cluster being tracked by the tech giant’s cybersecurity team. Since at least 2012, the state-sponsored threat actor is thought to have been active.

Trend Micro initially made TONESHELL public in November 2022 as a component of cyberattacks that targeted Taiwan, Japan, Australia, Myanmar, and the Philippines between May and October. Its main function, usually carried out using DLL side-loading read more about Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *