BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Mustang Panda Uses Kernel Rootkit to Deploy TONESHELL in SEA

Mustang Panda deploys a signed kernel-mode minifilter rootkit to inject TONESHELL into svchost.exe, protect files/registry/processes, and connect to C2 over TCP/443 — detection requires memory forensics.

  • Mustang Panda used a signed kernel-mode minifilter driver to load a new TONESHELL backdoor in mid-2025.
  • The malicious driver protects files, processes, and registry keys and injects TONESHELL into a spawned svchost.exe.
  • TONESHELL connects to C2 domains over TCP port 443 and supports file transfer and a remote shell.
  • Detection requires memory forensics because key components execute in memory and the driver hides API usage and I/O operations.

Mustang Panda deployed a previously undocumented kernel-mode rootkit driver in an attack detected in mid-2025 against an entity in Asia, with campaigns targeting government organizations in Myanmar and Thailand, according to Kaspersky. The driver registers as a Microsoft.com/en-us/Windows-hardware/drivers/ifs/about-file-system-filter-drivers”>minifilter driver, a type of file system filter that sits in the I/O stack to monitor or modify file operations.

- Advertisement -

The driver binary, named “ProjectConfiguration.sys,” is signed with a certificate issued to Guangzhou Kingteller Technology Co., Ltd that was valid from 2012 to 2015. “The driver file is signed with an old, stolen, or leaked digital certificate,” the report stated.

The Malware bundles two user-mode shellcodes embedded in the .data section and injects a small delay shellcode and then the TONESHELL backdoor into the same spawned svchost.exe. “The rootkit functionality protects both the driver’s own module and the user-mode processes into which the backdoor code is injected,” researchers said.

Key driver capabilities include resolving kernel APIs by hashing, blocking file-delete and file-rename operations, denying access to protected registry keys via a RegistryCallback routine, and intercepting process operations for listed process IDs. The driver also alters the altitude used by filters (see allocated altitudes) to bypass lower-altitude antivirus filters.

The TONESHELL implant establishes a TCP connection to C2 domains (for example, avocadomechanism[.]com and potherbreference[.]com) over port 443. Commands include creating temporary files, downloading and uploading files, canceling transfers, establishing a remote shell, receiving operator commands, and closing the connection.

- Advertisement -

Researchers note this is the first observed use of a kernel-mode loader for TONESHELL, increasing stealth and resilience. Memory forensics is required to detect the in-memory shellcode and confirm infection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SharpLink CEO Says ETH “Winning” Amidst “Noise”

SharpLink CEO Joseph Chalom dismissed Ethereum criticism as "noise," highlighting its institutional lead in...

Gravity Bridge Drained of $5.4M, Halted After Exploit

The Gravity Bridge, a cross-chain bridge between Ethereum and Cosmos, was exploited for roughly...

Micron Stock $5k by 2030? Forecasts Show Likely Shortfall

Transforming a $500 investment in Micron stock into $5,000 by 2030 would require a...

Candidate sells 10 Bitcoin for $800K to fund campaign

Republican candidate Michael Carbonara sold 10 Bitcoin for $800,000 in USDC to self-fund his...

ARK Buys HOOD, Trims During Rally, Adds Defense Stock

Ark Invest sold $13.6 million worth of Robinhood (HOOD) shares on Friday, profit-taking as...

Must Read

A Beginner’s Guide To Cryptocurrency Mining

Cryptocurrency is considered one of the most popular forms of financial assets today. Many of these digital assets operate within blockchain technology which works...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading