PULSE NAME
The HoneyMyte APT now protects malware with a kernel-mode rootkit
WHITE MUSTANG PANDA AlienVault 2025-12-29 Modified: 2025-12-29
5
IOCs
LOW VOLUME
In mid-2025, a malicious driver file was discovered on Asian computer systems, signed with a compromised digital certificate. This driver injects a backdoor Trojan and protects malicious files, processes, and registry keys. The final payload is a new variant of the ToneShell backdoor, associated with the HoneyMyte APT group. The attacks, which began in February 2025, primarily target government organizations in Southeast and East Asia, especially Myanmar and Thailand. The malware uses various techniques to evade detection, including API obfuscation, process protection, and registry key protection. The ToneShell backdoor communicates with command-and-control servers using fake TLS headers and supports remote operations such as file transfer and shell access.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ToneShell PlugX - S0013 Thoper TVT DestroyRAT Sogu Kaba Korplug ToneDisk
Indicators of Compromise (5)
All FileHash-MD5 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 36f121046192b7cac3e4bec491e8f1b5 2025-12-29
FileHash-MD5 abe44ad128f765c14d895ee1c8bad777 2025-12-29
FileHash-MD5 fe091e41ba6450bcf6a61a2023fe6c83 2025-12-29
domain avocadomechanism.com 2025-12-29
domain potherbreference.com 2025-12-29