Skip to content
ThreatCluster

Mustang Panda Deploys TONESHELL Malware via Windows Rootkit

First seen 31 Dec 2025, 17:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Chinese-linked group Mustang Panda has utilized a kernel-level rootkit to implant undetectable TONESHELL malware in Windows systems. This attack primarily targets Southeast Asian nations, indicating a strategic focus on the region. The malware's stealth capabilities pose significant risks to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (1)

Following this threat?

Track Mustang Panda and ToneShell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed