Chinese Hackers Use Rootkit to Hide ToneShell Malware Activity
ID: 05c22c62-9d23-5665-86f7-e6b66a3f80b9
STIX ID: report--05c22c62-9d23-5665-86f7-e6b66a3f80b9
Feed Name: cybersecurityNews.com
A Chinese-linked APT known as HoneyMyte (Mustang Panda / Bronze President) is deploying a stolen-code-signed kernel mini-filter driver (ProjectConfiguration.sys) as a rootkit to inject and conceal the ToneShell backdoor on Windows systems, primarily targeting government networks across Southeast and East Asia for long-term espionage. The driver hides files and processes, hooks file and registry operations to return access-denied at kernel level, alters Microsoft Defender filter altitude to intercept security operations, and enables ToneShell to communicate with C2 servers over raw TCP port 443 using a simple TLS-like header and XOR-encrypted payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
