By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
Computing

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

News Room
Last updated: 2025/12/30 at 4:02 AM
News Room Published 30 December 2025
Share
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
SHARE

Dec 30, 2026Ravie LakshmananMalware / Cyber Espionage

The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia.

The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by the hacking group targeting government organizations in Southeast and East Asia, primarily Myanmar and Thailand.

“The driver file is signed with an old, stolen, or leaked digital certificate and registers as a minifilter driver on infected machines,” the Russian cybersecurity company said. “Its end-goal is to inject a backdoor trojan into the system processes and provide protection for malicious files, user-mode processes, and registry keys.”

The final payload deployed as part of the attack is TONESHELL, an implant with reverse shell and downloader capabilities to fetch next-stage malware onto compromised hosts. The use of TONESHELL has been attributed to Mustang Panda since at least late 2022.

As recently as September 2025, the threat actor was linked to attacks targeting Thai entities with TONESHELL and a USB worm named TONEDISK (aka WispRider) that uses removable devices as a distribution vector for a backdoor referred to as Yokai.

The command-and-control (C2) infrastructure used for TONESHELL is said to have been erected in September 2024, although there are indications that the campaign itself did not commence until February 2025. The exact initial access pathway used in the attack is not clear. It’s suspected that the attackers abused previously compromised machines to deploy the malicious driver.

Cybersecurity

The driver file (“ProjectConfiguration.sys”) is signed with a digital certificate from Guangzhou Kingteller Technology Co., Ltd, a Chinese company that’s involved in the distribution and provisioning of automated teller machines (ATMs). The certificate was valid from August 2012 to 2015.

Given that there are other unrelated malicious artifacts signed with the same digital certificate, it’s assessed that the threat actors likely leveraged a leaked or stolen certificate to realize their goals. The malicious driver comes fitted with two user-mode shellcodes that are embedded into the .data section of the binary. They are executed as separate user-mode threads.

“The rootkit functionality protects both the driver’s own module and the user-mode processes into which the backdoor code is injected, preventing access by any process on the system,” Kaspersky said.

The driver has the following set of features –

  • Resolve required kernel APIs dynamically at runtime by using a hashing algorithm to match the required API addresses
  • Monitor file-delete and file-rename operations to prevent itself from being removed or renamed
  • Deny attempts to create or open Registry keys that match against a protected list by setting up a RegistryCallback routine and ensuring that it operates at an altitude of 330024 or higher
  • Interfere with the altitude assigned to WdFilter.sys, a Microsoft Defender driver, and change it to zero (it has a default value of 328010), thereby preventing it from loaded into the I/O stack
  • Intercept process-related operations and deny access if the action targets any process that’s on a list of protected process IDs when they are running
  • Remove rootkit protection for those processes once execution completes

“Microsoft designates the 320000–329999 altitude range for the FSFilter Anti-Virus Load Order Group,” Kaspersky explained. “The malware’s chosen altitude exceeds this range. Since filters with lower altitudes sit deeper in the I/O stack, the malicious driver intercepts file operations before legitimate low-altitude filters like antivirus components, allowing it to circumvent security checks.”

The driver is ultimately designed to drop two user-mode payloads, one of which spawns an “svchost.exe” process and injects a small delay-inducing shellcode. The second payload is the TONESHELL backdoor that’s injected into that same “svchost.exe” process.

Once launched, the backdoor establishes contact with a C2 server (“avocadomechanism[.]com” or “potherbreference[.]com”) over TCP on port 443, using the communication channel to receive commands that allow it to –

  • Create temporary file for incoming data (0x1)
  • Download file (0x2 / 0x3)
  • Cancel download (0x4)
  • Establish remote shell via pipe (0x7)
  • Receive operator command (0x8)
  • Terminate shell (0x9)
  • Upload file (0xA / 0xB)
  • Cancel upload (0xC), and
  • Close connection (0xD)
Cybersecurity

The development marks the first time TONSHELL has been delivered through a kernel-mode loader, effectively allowing it to conceal its activity from security tools. The findings indicate that the driver is the latest addition to a larger, evolving toolset used by Mustang Panda to maintain persistence and hide its backdoor.

Memory forensics is key to analyzing the new TONESHELL infections, as the shellcode executes entirely in memory, Kaspersky said, noting that detecting the injected shellcode is a crucial indicator of the backdoor’s presence on compromised hosts.

“HoneyMyte’s 2025 operations show a noticeable evolution toward using kernel-mode injectors to deploy ToneShell, improving both stealth and resilience,” the company concluded.

“To further conceal its activity, the driver first deploys a small user-mode component that handles the final injection step. It also uses multiple obfuscation techniques, callback routines, and notification mechanisms to hide its API usage and track process and registry activity, ultimately strengthening the backdoor’s defenses.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article TSMC and Intel slow expansion in Japan and Malaysia due to weak chip demand and economic uncertainty · TechNode TSMC and Intel slow expansion in Japan and Malaysia due to weak chip demand and economic uncertainty · TechNode
Next Article AI agents arrived in 2025 – here’s what happened and the challenges ahead in 2026 AI agents arrived in 2025 – here’s what happened and the challenges ahead in 2026
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Get the Support You Need With the Best WIRED-Tested Body Pillows for Side Sleepers
Get the Support You Need With the Best WIRED-Tested Body Pillows for Side Sleepers
Gadget
Huawei unveils multi-agent architecture to advance intelligent wireless networks at MWC Shanghai · TechNode
Huawei unveils multi-agent architecture to advance intelligent wireless networks at MWC Shanghai · TechNode
Computing
Plaud Note Pro is an excellent AI-powered recorder that I carry everywhere |  News
Plaud Note Pro is an excellent AI-powered recorder that I carry everywhere | News
News
Urgent warning as popular TV device stops working in 48 hours – upgrade now
Urgent warning as popular TV device stops working in 48 hours – upgrade now
News

You Might also Like

Huawei unveils multi-agent architecture to advance intelligent wireless networks at MWC Shanghai · TechNode
Computing

Huawei unveils multi-agent architecture to advance intelligent wireless networks at MWC Shanghai · TechNode

1 Min Read
How to Batch Content for Social Media (Instagram, Tiktok, YouTube, & more)
Computing

How to Batch Content for Social Media (Instagram, Tiktok, YouTube, & more)

12 Min Read
The TechBeat: The Hidden Cost of AI: Why It’s Making Workers Smarter, but Organisations Dumber (12/30/2025) | HackerNoon
Computing

The TechBeat: The Hidden Cost of AI: Why It’s Making Workers Smarter, but Organisations Dumber (12/30/2025) | HackerNoon

7 Min Read
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware
Computing

Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

6 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?