Evasive Panda APT Cyberespionage Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 29, 2025; most recent activity December 29, 2025.
The Evasive Panda APT Cyberespionage Campaign is a covert cyber espionage operation attributed to a threat actor group and characterized by stealthy, long-running intrusions. Recent reporting highlights its use of kernel-mode rootkit techniques to deploy the ToneShell payload, indicating a focus on deep system compromise and evasion of conventional defenses. This combination of kernel-space malware and targeted espionage makes it a significant risk for targeted organizations and high-value data exfiltration efforts.
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…