ToneDisk is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 29, 2025; most recent activity December 29, 2025.
ToneDisk is a malware family linked to the HoneyMyte APT operations. It employs a kernel-mode rootkit to deploy ToneShell, reflecting an escalation to kernel-level capabilities that improves stealth and persistence. This development underscores the group's focus on deep OS integration to evade defenses and maintain footholds in targeted environments.
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…