TONESHELL
S1239 · Windows
TONESHELL is a custom backdoor that has been used since at least Q1 2021. TONESHELL malware has previously been leveraged by Chinese affiliated actors identified as Mustang Panda.
ATT&CK S1239
Sigma rules0
YARA rules0
Live IOCs0