#ToneShell
IBM X-Force has published a technical report on SnakeDisk, a USB worm linked to Hive0154, a Chinese cyber-espionage group also known as Mustang Panda

www.ibm.com/think/x-forc...
Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm | IBM
Hive0154 wreaks havoc on Singapore and Thailand using a new Toneshell backdoor and SnakeDisk USB worm.
www.ibm.com
September 16, 2025 at 9:02 AM
A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
Chinese state hackers use rootkit to hide ToneShell malware activity
A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
www.bleepingcomputer.com
December 30, 2025 at 12:08 AM
"Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit: The threat actor uses a signed driver file containing two user-mode shellcodes to execute its ToneShell backdoor." via Security Week www.securityweek.com/chinese-apt-...
Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit
The China-linked Mustang Panda APT has been using a kernel-mode rootkit in attacks leading to ToneShell backdoor deployments.
www.securityweek.com
December 30, 2025 at 7:18 PM
China-backed hackers are deploying TONESHELL v3, StarProxy, and stealth tools like SplatCloak to breach Myanmar targets—dodging EDR, logging keystrokes, and hopping across networks with FakeTLS tricks.
Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates
Mustang Panda uses StarProxy, SplatCloak, and updated TONESHELL to breach Myanmar target undetected.
thehackernews.com
April 18, 2025 at 2:12 AM
• 3 TONESHELL variants
• 2 new keyloggers (PAKLOG, CorKLOG)
• StarProxy – a lateral movement proxy over FakeTLS
• SplatCloak – a Windows kernel-level EDR evasion driver
#Cybersecurity
thehackernews.com/2025/04/must...
Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates
Mustang Panda uses StarProxy, SplatCloak, and updated TONESHELL to breach Myanmar target undetected.
thehackernews.com
April 18, 2025 at 2:12 AM
China's Mustang Panda used MAVInject.exe to inject TONESHELL malware (via IRSetup.exe & decoy PDF) into waitfor.exe, bypassing ESET. The Thailand-targeting attack communicated with militarytc[.]com:443.#MustangPandaMAVInject
February 18, 2025 at 4:06 PM
Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome
Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome
cybersecuritynews.com
August 6, 2025 at 4:08 PM
Chinese hackers (Mustang Panda) use ToneShell & StarProxy to bypass EDR, masking malicious traffic via FakeTLS. Targeting East Asian government/military, IOCs (MD5s, network indicators) are available.#MustangPandaFakeTLSAttack
April 17, 2025 at 2:09 PM
Excellent write up from folks over at ZScaler for #MustangPanda related activities. Per usual, the group's focused attacks and TOnePipeShell/TOneShell usage continues, alongside custom tools and an EDR blocker designed specifically to target Microsoft/Kaspersky EDRs. also a lil cameo from me
April 18, 2025 at 4:54 AM
The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by the hacking group targeting government organizations in Southeast and East Asia, primarily Myanmar and Thailand. thehackernews.com/2025/12/must...
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
Mustang Panda deployed TONESHELL via a signed kernel-mode rootkit, targeting Asian government networks and evading security tools.
thehackernews.com
December 30, 2025 at 1:29 PM
Chinese state hackers use rootkit to hide ToneShell malware activity
Chinese state hackers use rootkit to hide ToneShell malware activity
A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
www.bleepingcomputer.com
December 30, 2025 at 12:20 AM
中国政府系ハッカー、ルートキットを使ってToneShellマルウェアの活動を隠蔽
#CybersecurityNews
www.bleepingcomputer.com/news/securit...
Chinese state hackers use rootkit to hide ToneShell malware activity
A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
www.bleepingcomputer.com
January 4, 2026 at 5:52 AM
Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems gbhackers.com/mustang-pand...
Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems
IBM X-Force researchers have uncovered sophisticated new malware campaigns orchestrated by the China-aligned threat actor Hive0154.
gbhackers.com
September 14, 2025 at 11:27 AM
Intezer analyses a new ToneShell backdoor variant linked to Mustang Panda. It’s delivered via DLL sideloading with signed EXEs and cloud-hosted lures in ongoing operations against Myanmar. intezer.com/blog/franken...
September 12, 2025 at 10:40 AM
Notícia da SecurityWeek

"Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit" #bolhasec
Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit
The China-linked Mustang Panda APT has been using a kernel-mode rootkit in attacks leading to ToneShell backdoor deployments.
www.securityweek.com
February 18, 2026 at 12:30 PM