Researchers identify new ToneShell backdoor targeting government agencies

  • Mustang Panda deployed upgraded ToneShell backdoors against Asian government organizations
  • New variant uses signed mini-filter driver, enabling rootkit-like stealth and Defender tampering
  • Kaspersky advises memory forensics and IoCs to detect infections in compromised systems

Chinese state-sponsored threat actors, known as Mustang Panda, have been observed targeting government organizations of various Asian countries with an upgraded version of the ToneShell backdoor.

This is according to cybersecurity researchers Kaspersky, who recently analyzed a malicious file driver they found on computers belonging to government organizations in Myanmar, Thailand, and others.

The driver led to the discovery of ToneShell, a backdoor which grants attackers unabated access to compromised devices, through which they can upload and download files, create new documents, and more.

Mini-filters and kernel-mode drivers

The new variant came with improvements, Kaspersky added, including establishing a remote shell via a pipe, terminating shell, cancelling uploads, closing connections, creating temporary files for incoming data, and more.

ToneShell is generally used for cyber-espionage campaigns. Victim computers were apparently also infected with other malware, as well, including PlugX, and the ToneDisk USB worm. The campaign likely started in February 2025, researchers speculate.

But what makes this campaign really stand out is the use of a mini-filter driver that was signed with either a stolen, or leaked certificate.

“This is the first time we’ve seen ToneShell delivered through a kernel-mode loader, giving it protection from user-mode monitoring and benefiting from the rootkit capabilities of the driver that hides its activity from security tools,” Kaspersky said.

Mini-filters are kernel-mode drivers that sit inside the Windows file system stack and intercept file system operations in real time. They let software see, block, modify, or log file activity before it reaches the disk, and are part of Microsoft’s File System Filter Manager framework.

Among other things, they let the attackers tamper with Microsoft Defender, making sure it doesn’t get loaded into the I/O stack.

To defend against the new attacks, the researchers advise memory forensics as the number one way of spotting ToneShell infections. They also shared a list of indicators of compromise (IoC) which can be used to determine if a system was attacked or not.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

LG will release the first 1000Hz, 1080p gaming monitor this year

If you just can't choose between refresh rate and resolution, LG's next gaming monitor could solve your problem, as the UltraGear 25G590B monitor is...

YouTube removes dedicated ‘Subscriptions’ tab from mobile app in new test

YouTube is no stranger to redesigns, but the next one could throw your muscle memory for a loop. The mobile app might be getting...

Volvo teases a new affordable EV to replace discontinued EX30

Volvo's compact, quirky EX30 had a lot of problems when it was first released. Tariffs essentially erased its affordability, making it more expensive to...

Sony is raising short-subscription prices for PlayStation Plus

Sony is hiking the starting price of one-month and three-month PlayStation Plus subscriptions in "select regions," blaming "ongoing market conditions." Beginning May 20th, 1-month...

Google is rolling out its redesigned Workspace app icons

It's not just you - the Google Workspace apps are getting a new look. The redesigned app icons, leaked last month, are now rolling...

Elon Musk loses his case against Sam Altman

After around two hours of deliberation, the jury has reached a unanimous verdict in Musk v. Altman, the tech trial of the year. The...

Dyson’s super-slim PencilWash just hit its best price to date for Memorial Day

If Dyson’s PencilVac Fluffycones made you wish the company had built something similarly slim for scrubbing the hard floors in your home, enter the...

Walmart launches new budget-friendly Android tablets starting at $97

Walmart's Onn brand just launched a whole line of budget-friendly Android tablets that, all together, cost less in total than a single iPad Pro....

Musk v. Altman proved that AI is led by the wrong people

The tech trial of the year, Musk v. Altman, was ultimately a fight for control. Elon Musk argued that Sam Altman, with whom he...

PlayStation exclusives aren’t coming to PC anymore

Sony reportedly won't release its major single-player PlayStation games on PC anymore. According to Bloomberg's Jason Schreier, Hermen Hulst, who heads up PlayStation's studios...