Mustang Panda Deploys ToneShell Backdoor via Signed Kernel-Mode Rootkit

Mustang Panda Deploys ToneShell Backdoor via Signed Kernel-Mode Rootkit

First seen 30 Dec 2025, 19:25 UTC YoutubeFeeds.FeedburnerSecurityaffairs.CoSecurityaffairsScworld 80% similarity 50.6

Article Content

Browse articles
ThreatCluster

In mid-2025, the Chinese APT group Mustang Panda launched cyber-espionage attacks using a signed kernel-mode rootkit to deploy the ToneShell backdoor. The attacks targeted government organizations in Southeast and East Asia, including Myanmar and Thailand, and utilized advanced techniques to evade detection by security software like Microsoft Defender.

ThreatCluster AI

Community

Browse all →