ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit
ID: 2a24b01e-dd99-5a46-b3ca-85a6b39ae26c
STIX ID: report--2a24b01e-dd99-5a46-b3ca-85a6b39ae26c
Feed Name: Hunt.io Blog
Threat Score
**Executive summary:** This report analyzes a ToneShell backdoor campaign attributed to the Mustang Panda APT that used an IISS-themed lure to distribute a malicious PIF which drops SFFWallpaperCore.exe and libemb.dll (ToneShell/PubLoad behaviors), establishes persistence, and communicates with C2 infrastructure hosted on Topway Global Limited IP space; the report includes file hashes, C2 IPs, ASN/certificate details, and behavioral analysis to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
