ToneDisk Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 29, 2025
Last Seen
December 29, 2025

ToneDisk is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 29, 2025; most recent activity December 29, 2025.

Overview

ToneDisk is a malware family linked to the HoneyMyte APT operations. It employs a kernel-mode rootkit to deploy ToneShell, reflecting an escalation to kernel-level capabilities that improves stealth and persistence. This development underscores the group's focus on deep OS integration to evade defenses and maintain footholds in targeted environments.

Related Threat Clusters

  • HoneyMyte APT Campaign Deploys ToneShell via Kernel-Mode Rootkit

    The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…

    2 articles · Updated December 29, 2025

Recent Intelligence Reports

  • HoneyMyte APT Campaign Uses Kernel-Mode Rootkit to Deploy ToneShell — Technadu · December 29, 2025
  • The HoneyMyte APT evolves with a kernel — Securelist · December 29, 2025

CVSS v3.1 Breakdown