Chinese state hackers use #rootkit to hide #ToneShell #malware activity
Chinese state hackers use #rootkit to hide #ToneShell #malware activity
HoneyMyte aka Mustang Panda is using a signed rootkit to drop the #ToneShell backdoor in ongoing attacks, hiding its activity from security tools and giving attackers remote access to system.
Read: https://hackread.com/honeymyte-mustang-panda-toneshell-backdoor/
New ToneShell Backdoor With New Features Leverage Task Scheduler COM Service for Persistence
https://cybersecuritynews.com/new-toneshell-backdoor-with-new-features-leverage/
#Infosec #Security #Cybersecurity #CeptBiro #ToneShell #Backdoor #NewFeatures #TaskScheduler #COMService #Persistence
Since its first appearance earlier this year, the ToneShell backdoor has demonstrated a remarkable capacity for adaptation, toyed with by the Mustang Panda group to maintain an enduring foothold in targeted environments. This latest variant, discovered in early September, arrives concealed within sideloaded DLLs alongside legitimate executables. Delivered via compressed archives purporting to contain innocuous […]
Today, Trend Micro reported that Mustang Panda (Earth Preta) is leveraging MAVInject.exe to bypass ESET antivirus, injecting malware into waitfor.exe to maintain persistence. This TONESHELL backdoor sideloads through OriginLegacyCLI.exe, targets Thailand-based users, and establishes C2 communication via militarytc[.]com.
ESET disputes this as a “bypass,” stating their protections have been in place for years. The real takeaway? Memorizing security policies won’t stop real attackers—understanding how they actually operate will.
APT groups innovate, exploit OS-native tools, and evade detection in ways policy documents can’t prepare you for. We need hands-on defenders who understand malware behavior, not just non-technical compliance checkboxes and certifications which focus on worthless memorization rather than understanding computer and network architecture.
#CyberSecurity #ThreatHunting #RedTeam #APT #MustangPanda #MAVInject #TONESHELL
https://thehackernews.com/2025/02/chinese-hackers-exploit-mavinjectexe-to.html
"Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities"
#MustangPanda #APT #cyberattack #cybercrime #cyberwar #cyberespionage
#spearphishing / #PUBLOAD #TONEINS #TONESHELL #malware
https://thehackernews.com/2022/12/chinese-hackers-using-russo-ukrainian.html