{"id":868,"date":"2025-12-30T09:14:55","date_gmt":"2025-12-30T07:14:55","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=868"},"modified":"2026-01-05T09:15:44","modified_gmt":"2026-01-05T07:15:44","slug":"mustang-panda-uses-signed-kernel-mode-rootkit-to-load-toneshell-backdoor","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/12\/30\/mustang-panda-uses-signed-kernel-mode-rootkit-to-load-toneshell-backdoor\/","title":{"rendered":"Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Chinese hacking group known as&nbsp;<strong><a href=\"https:\/\/thehackernews.com\/2025\/08\/unc6384-deploys-plugx-via-captive.html\" rel=\"noreferrer noopener\" target=\"_blank\">Mustang Panda<\/a><\/strong>&nbsp;(aka HoneyMyte) has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by the hacking group targeting government organizations in Southeast and East Asia, primarily Myanmar and Thailand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2025\/12\/mustang-panda-uses-signed-kernel-driver.html\">Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Chinese hacking group known as&nbsp;Mustang Panda&nbsp;(aka HoneyMyte) has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia. The findings come from Kaspersky, which observed the new backdoor variant in&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[40],"class_list":["post-868","post","type-post","status-publish","format-standard","hentry","category-malware","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/868","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=868"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/868\/revisions"}],"predecessor-version":[{"id":869,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/868\/revisions\/869"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}