logo

The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments

ID: b0a839fc-0902-5f48-b5a1-b60b5a49c6ea

STIX ID: report--b0a839fc-0902-5f48-b5a1-b60b5a49c6ea

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Kaspersky Labs uncovered a mid-2025 HoneyMyte (Mustang Panda/Bronze President) campaign using a signed kernel-mode driver (ProjectConfiguration.sys) as a loader/bodyguard to deploy the ToneShell backdoor and harden persistence on government networks in Myanmar and Thailand; the rootkit manipulates driver altitude to disable Microsoft Defender components, communicates with C2 using fake TLS 1.3 headers (e.g., avocadomechanism.com), and ties to known HoneyMyte tools like PlugX and ToneDisk, indicating a sophisticated, stealthy, and ongoing espionage operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.