Tag: TONESHELL Backdoor

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
News

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

In a cyberattack discovered in mid-2025 that targeted an unidentified Asian entity, the Chinese hacker collective Mustang Panda used an undocumented kernel-mode rootkit driver to deliver a new backdoor variant known as TONESHELL. Kaspersky conducted cyber espionage efforts against government agencies in Southeast and East Asia, namely Myanmar and Thailand, and discovered the new backdoor variant. According to the Russian cybersecurity firm, the driver file registers as a minifilter driver on compromised computers and is signed with an outdated, stolen, or compromised digital certificate. Its ultimate objective is to safeguard registry keys, user-mode processes, and harmful files by inserting a backdoor trojan into system processes. TONESHELL, an implant with reverse shell and dow...