TONESHELL

MITRE ATT&CK: S1239 View on attack.mitre.org

Aliases: TONESHELL

First seen
2021-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
4 (4 malicious)
Last IoC activity
2026-08-06 11:38:10
Profile updated
2026-07-07 12:54:17

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:cn country_code:us country_code:kr

Context

TONESHELL is a custom backdoor that has been used since at least Q1 2021. TONESHELL malware has previously been leveraged by Chinese affiliated actors identified as Mustang Panda.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to TONESHELL (S1239). The 4 most recently updated:

Detection coverage

  • 3 YARA rules
  • 563 Sigma rules

Malware & tools used

  • Environmental Keying (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Delay Execution (attack-pattern)
  • Screen Capture (attack-pattern)
  • User Activity Based Checks (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Dynamic API Resolution (attack-pattern)
  • DLL (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Non-Standard Encoding (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Keylogging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Code Signing (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Toneshell_Shellcode (yara-rule)
  • SEKOIA_Apt_Mustang_Panda_Toneshell (yara-rule)
  • SEKOIA_Apt_Toneshell_Loader (yara-rule)

Reports & references

  • Trend Micro — Earth Preta Spear Phishing Governments Worldwide (report)
  • blog.sekoia.io — My Teas Not Cold An Overview Of China Cyber Threat (report)
  • ESET — Separating Bee Panda Ceranakeeper Making Beeline Thailand (report)
  • csirt-cti.net — Stately Taurus Targets Myanmar (report)
  • Palo Alto Unit 42 — Stately Taurus Attacks Se Asian Government (report)
  • attackiq.com — Emulating The Politically Motivated Chinese Apt Mustang Panda (report)
  • zscaler.com — Latest Mustang Panda Arsenal Toneshell And Starproxy P1 (report)
  • hitcon.org — Sailing The Seven Seas Deep Dive Into Polaris Arsenal And Intelligence Insights (report)
  • github.com — 2024 08 Sailing%20The%20Seven%20Seas (report)
  • ibm.com — Hive0154 Drops Updated Toneshell Backdoor (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Toneshell (report)
  • hunt.io — Toneshell Backdoor Used To Target Attendees Of The Iiss Defence Summit (report)
  • MITRE ATT&CK — S1239 (report)

External references