The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
ID: b0a839fc-0902-5f48-b5a1-b60b5a49c6ea
STIX ID: report--b0a839fc-0902-5f48-b5a1-b60b5a49c6ea
Feed Name: securityonline.info
Kaspersky Labs uncovered a mid-2025 HoneyMyte (Mustang Panda/Bronze President) campaign using a signed kernel-mode driver (ProjectConfiguration.sys) as a loader/bodyguard to deploy the ToneShell backdoor and harden persistence on government networks in Myanmar and Thailand; the rootkit manipulates driver altitude to disable Microsoft Defender components, communicates with C2 using fake TLS 1.3 headers (e.g., avocadomechanism.com), and ties to known HoneyMyte tools like PlugX and ToneDisk, indicating a sophisticated, stealthy, and ongoing espionage operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
