logo

Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver

ID: 899fb8e8-6675-5778-afe8-15c7655ad49a

STIX ID: report--899fb8e8-6675-5778-afe8-15c7655ad49a

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-12-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Mustang Panda (HoneyMyte) deployed a signed kernel-mode rootkit driver (ProjectConfiguration.sys) containing embedded shellcode to inject and protect the ToneShell backdoor on targeted systems in Southeast and East Asia; the driver manipulates registry altitudes to disable Microsoft Defender components, intercepts handle operations to protect injected processes, and uses a marker file plus raw TCP-over-443 (fake TLS) for C2, according to Kaspersky's analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.