HoneyMyte APT Campaign Deploys ToneShell via Kernel-Mode Rootkit
First seen 29 Dec 2025, 18:23 UTC
•
•80% similarity
•53.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit to hide the attacker's presence and injects the backdoor into system processes.
ThreatCluster AI