ThreatCluster

Mustang Panda Deploys TONESHELL Malware via Windows Rootkit

First seen 31 Dec 2025, 17:21 UTC Cybernews 57% similarity 34

Article Content

Browse articles
ThreatCluster

The Chinese-linked group Mustang Panda has utilized a kernel-level rootkit to implant undetectable TONESHELL malware in Windows systems. This attack primarily targets Southeast Asian nations, indicating a strategic focus on the region. The malware's stealth capabilities pose significant risks to affected systems.

ThreatCluster AI

Community

Browse all →

Tracked Entities in This Story