HoneyMyte APT Campaign Deploys ToneShell via Kernel-Mode Rootkit

HoneyMyte APT Campaign Deploys ToneShell via Kernel-Mode Rootkit

First seen 29 Dec 2025, 18:23 UTC SecurelistTechnadu 80% similarity 53.7

Article Content

Browse articles
ThreatCluster

The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit to hide the attacker's presence and injects the backdoor into system processes.

ThreatCluster AI

Community

Browse all →