Mustang Panda Deploys TONESHELL Malware via Windows Rootkit
First seen 31 Dec 2025, 17:21 UTC
•
•57% similarity
•34
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Chinese-linked group Mustang Panda has utilized a kernel-level rootkit to implant undetectable TONESHELL malware in Windows systems. This attack primarily targets Southeast Asian nations, indicating a strategic focus on the region. The malware's stealth capabilities pose significant risks to affected systems.
ThreatCluster AI