The Chinese Mustang Panda group is using an updated version of a backdoor called TONESHELL and a new USB worm called SnakeDisk .

According to IBM X-ForceGolo Mühr and Joshua Chung, researchers the worm only runs on devices with IP addresses in Thailand and installs the Yokai backdoor . The tech giant's cybersecurity unit is tracking the cluster under the name Hive0154 , which is also referred to as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, Polaris, RedDelta, Stately Taurus, and Twill Typhoon. The state-backed threat actor is believed to have been active since at least 2012.
TONESHELL was first documented by Trend Microin November 2022 as part of cyberattacks targeting Myanmar, Australia, the Philippines, Japan, and Taiwan. It is typically executed via DLL side-loading, with its primary responsibility to download secondary payloads to the infected computer.
See also: BlackNevas Ransomware encrypts files and steals data
Typical attack chains include the use of spear-phishing emails to install malware families such as PUBLOAD or TONESHELL. PUBLOAD, which operates similarly to TONESHELL, is capable of downloading shellcode payloads via HTTP POST requests from a command and control (C2) server.
The new variants of TONESHELL, dubbed TONESHELL8 and TONESHELL9 by IBM X-Force, support C2 communication via locally configured proxy servers to integrate with enterprise network traffic and facilitate two active reverse shells in parallel. It also embeds useless code, copied from OpenAI’s ChatGPT website, into the malware’s functionality. It does this to evade detection and resist analysis.
Also, as mentioned above, Mustang Panda also uses the USB worm SnakeDisk, which is launched via DLL side-loading. This worm shares elements with TONEDISK (also known as WispRider), another USB worm framework in the TONESHELL family. It is primarily used to detect new and existing USB devices connected to the computer, using them as a means of propagation.
See also: New SEO Poisoning Attack Targets Windows Users

Specifically, it moves existing files on the USB to a new subdirectory, effectively tricking the victim into clicking the malicious payload on a new machine by setting its name to the USB device's volume name, or “USB.exe.” Once the malware is launched, the files are copied back to their original location.
A notable feature of the malware is that it is geofenced, so that it only executes on public IP addresses geolocated in Thailand. SnakeDisk also acts as a conduit for the installation of Yokai, a backdoor that creates a reverse shell to execute arbitrary commands. It was previously analyzed by Netskopein attacks targeting Thai officials.
Yokai shares commonalities with other backdoor families attributed to Hive0154, such as PUBLOAD/PUBSHELL and TONESHELL. While these families are separate pieces of malware, they follow roughly the same structure and use similar techniques to create reverse shells with their C2 server.
See also: DarkCloud Stealer targets financial institutions

The use of SnakeDisk and Yokai likely indicates a subgroup within Mustang Panda that is hyper-focused on Thailand, while also highlighting the continued evolution and improvement of the threat agent's arsenal.
Mustang Panda evolves its techniques
Mustang Panda confirms that modern threats are evolving with a strategic approach: targeted action, persistent presence and exploitation of weak points in the software supply chain. The essence of defense is no longer just technical — it is about processes, training and constant monitoring. Essential measures include strict control of removable media, enforcing least-privilege policies, continuous monitoring of behavioral anomalies and isolation of critical endpoints. Organizations should also incorporate tabletop exercises, regular threat hunting and rapid exchange of indicators with third parties. Technology providers should strengthen security updates, share indicators and implement least privilege policies without delay.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
