TONESHELL
MITRE ATT&CK: S1239 View on attack.mitre.org
Aliases: TONESHELL
- First seen
- 2021-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2026-08-06 11:38:10
- Profile updated
- 2026-07-07 12:54:17
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:cn country_code:us country_code:kr
Context
TONESHELL is a custom backdoor that has been used since at least Q1 2021. TONESHELL malware has previously been leveraged by Chinese affiliated actors identified as Mustang Panda.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to TONESHELL (S1239). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2026-08-06_593e188c671d57909aac095a3734815b_amadey_cobalt-strike_elex_luca-st... | 2026-08-06 | 1 |
| file sample | 2026-08-05_5cd4b061af6a81519fa31927d05eab97_amadey_elex_hellokitty_luca-steal... | 2026-08-05 | 1 |
| file sample | 5afe21142999659a4050f6e038a6dab96cf4827f332497049a91cdb1a4d4828b | 2026-07-31 | 2 |
| file sample | edb0025d79d00839cc52d6b750d845c37ffd5a882c81e7979e2594a7f6c6d361 | 2026-07-30 | 1 |
Detection coverage
- 3 YARA rules
- 563 Sigma rules
Malware & tools used
- Environmental Keying (attack-pattern)
- Execution Guardrails (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Security Software Discovery (attack-pattern)
- Delay Execution (attack-pattern)
- Screen Capture (attack-pattern)
- User Activity Based Checks (attack-pattern)
- Process Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- DLL (attack-pattern)
- Scheduled Task (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Non-Standard Encoding (attack-pattern)
- Local Storage Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Keylogging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Application Window Discovery (attack-pattern)
- Regsvr32 (attack-pattern)
- Code Signing (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Mustang Panda (threat-actor)
Detection rules
- SEKOIA_Apt_Toneshell_Shellcode (yara-rule)
- SEKOIA_Apt_Mustang_Panda_Toneshell (yara-rule)
- SEKOIA_Apt_Toneshell_Loader (yara-rule)
Reports & references
- Trend Micro — Earth Preta Spear Phishing Governments Worldwide (report)
- blog.sekoia.io — My Teas Not Cold An Overview Of China Cyber Threat (report)
- ESET — Separating Bee Panda Ceranakeeper Making Beeline Thailand (report)
- csirt-cti.net — Stately Taurus Targets Myanmar (report)
- Palo Alto Unit 42 — Stately Taurus Attacks Se Asian Government (report)
- attackiq.com — Emulating The Politically Motivated Chinese Apt Mustang Panda (report)
- zscaler.com — Latest Mustang Panda Arsenal Toneshell And Starproxy P1 (report)
- hitcon.org — Sailing The Seven Seas Deep Dive Into Polaris Arsenal And Intelligence Insights (report)
- github.com — 2024 08 Sailing%20The%20Seven%20Seas (report)
- ibm.com — Hive0154 Drops Updated Toneshell Backdoor (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Toneshell (report)
- hunt.io — Toneshell Backdoor Used To Target Attendees Of The Iiss Defence Summit (report)
- MITRE ATT&CK — S1239 (report)