logo

ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit

ID: 2a24b01e-dd99-5a46-b3ca-85a6b39ae26c

STIX ID: report--2a24b01e-dd99-5a46-b3ca-85a6b39ae26c

Feed Name: Hunt.io Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

**Executive summary:** This report analyzes a ToneShell backdoor campaign attributed to the Mustang Panda APT that used an IISS-themed lure to distribute a malicious PIF which drops SFFWallpaperCore.exe and libemb.dll (ToneShell/PubLoad behaviors), establishes persistence, and communicates with C2 infrastructure hosted on Topway Global Limited IP space; the report includes file hashes, C2 IPs, ASN/certificate details, and behavioral analysis to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.