HoneyMyte APT Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 29, 2025; most recent activity December 29, 2025.
The HoneyMyte APT Campaign is an advanced persistent threat operation that uses a kernel-mode rootkit to deploy the ToneShell payload. This approach indicates high sophistication, leveraging kernel-level stealth and persistence to gain deep system access and evade detection. ToneShell serves as the deployed backdoor enabling attacker control over compromised machines.
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…