A months-long espionage campaign linked to the Chinese group Mustang Panda has been identified, utilizing an updated variant of the FDMTP backdoor. This campaign, tracked by Darktrace, began in late September 2025 and…
Mustang Panda, a Chinese APT group, has shifted its focus to India's banking sector, utilizing the LOTUSLITE backdoor in recent campaigns. This activity, observed in March 2026, diverges from its typical targets, which…
The Mustang Panda group has intensified its cyber-espionage efforts by deploying a new variant of the CoolClient backdoor, which includes advanced infostealer capabilities. This updated malware targets government and…
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…
In mid-2025, the Chinese APT group Mustang Panda launched cyber-espionage attacks using a signed kernel-mode rootkit to deploy the ToneShell backdoor. The attacks targeted government organizations in Southeast and East…
A Chinese-linked threat group, associated with HoneyMyte, is utilizing a new kernel rootkit to obscure its ToneShell backdoor. This cyber campaign has primarily targeted government networks in Southeast and East Asia,…
The HoneyMyte APT group, also known as Mustang Panda or Bronze President, has enhanced its CoolClient malware to include capabilities for stealing browser login information. This upgrade poses a significant risk to…