logo

Chinese state hackers use rootkit to hide ToneShell malware activity

ID: 3fb135b1-da9c-5afb-bbfc-7d018cbbfe52

STIX ID: report--3fb135b1-da9c-5afb-bbfc-7d018cbbfe52

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-12-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky analyzed a new ToneShell backdoor sample used in Mustang Panda campaigns that is delivered via a signed kernel‑mode mini‑filter driver (ProjectConfiguration.sys) acting as a rootkit to hide activity and inject user‑mode payloads; the variant adds network obfuscation, a new host ID scheme, and remote file/shell capabilities, and has been observed in attacks against government organizations in Myanmar, Thailand and other Asian countries since at least February 2025, with a short IoC list provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.