A new sample of the ToneShell, commonly seen in Chinese cyberespionage campaigns, has been distributed via a kernel-mode loader in attacks against state organizations.
See also: 'Ink Dragon' threat group targets IIS servers

The malware is attributed to the Mustang Panda, also known as HoneyMyte or Bronze President, which mainly targets government agencies, NGOs, think tanks and other high-profile organizations globally.
Kaspersky security researchers analyzed a malicious driver found on computer systems in Asia and found that it has been used in attacks since at least February 2025, targeting government agencies in Myanmar, Thailand, and other Asian countries. The evidence showed that the compromised organizations had previously been infected with older versions of ToneShell, the PlugX malware , or the ToneDisk USB worm , which are also attributed to state-backed Chinese hackers.
According to Kaspersky, the new ToneShell was deployed via a mini-filter driver named ProjectConfiguration.sys, which was signed with a stolen digital certificate, valid from 2012–2015, issued to Guangzhou Kingteller Technology Co., Ltd.
See also: Chinese hackers exploit React2Shell vulnerability

Mini-filters are kernel-mode drivers that are integrated into the Windows file system I/O stack and can inspect, modify, or block file operations. They are commonly used by security software, encryption tools, and backup applications. ProjectConfiguration.sys contains two user-mode shellcodes in the .data section , which run as separate user-mode threads and are injected into user-mode processes.
To avoid static analysis, the driver resolves the necessary kernel APIs at runtime, recording the loaded kernel modules and matching function hashes, rather than directly injecting the functions.
Additionally, it registers as a mini-filter driver and interferes with file system operations related to deletion and renaming. When such actions target the driver itself, they are blocked, causing the request to fail.
Kaspersky points out that memory forensics is crucial for detecting ToneShell infections supported by the new kernel-level injector.
See also: CISA cites Chinese hackers using BRICKSTORM

Researchers state with a high degree of certainty that the new ToneShell backdoor sample is attributed to the Mustang Panda cyberespionage group . They also estimate that the threat actor has evolved its tactics, techniques, and procedures to achieve greater operational stealth and resilience.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
