Tuesday, 30 December 2025

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

iT4iNT SERVER The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia.
The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by the hacking group targeting VDS VPS Cloud


http://dlvr.it/TQ46Tk

No comments:

Post a Comment

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

iT4iNT SERVER The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady ...