BackBox.org News
  • BackBox.org
  • Linux
  • Community
  • News
  • Services
  • Sitemap
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

December 30, 2025/in General News

The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia.
The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by the hacking group targeting

The Hacker News – ​Read More

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png 0 0 admin https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png admin2025-12-30 09:06:462025-12-30 09:06:46Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
Search Search
Copyright © BackBox.org
  • Link to X
  • Link to Facebook
  • Link to LinkedIn
  • Link to Youtube
  • Link to Telegram
Link to: AI killed the cloud-first strategy: Why hybrid computing is the only way forward now Link to: AI killed the cloud-first strategy: Why hybrid computing is the only way forward now AI killed the cloud-first strategy: Why hybrid computing is the only way forward... Link to: Korean Air Data Compromised in Oracle EBS Hack Link to: Korean Air Data Compromised in Oracle EBS Hack Korean Air Data Compromised in Oracle EBS Hack
Scroll to top Scroll to top Scroll to top