ToneShell is a Windows backdoor family associated with the China-aligned espionage cluster commonly tracked as Mustang Panda, Earth Preta, Hive0154, HoneyMyte, and related aliases. The malware has evolved through multiple versions and has been used in espionage campaigns targeting government and strategic-sector organizations, including operations against entities in India and Myanmar. It is commonly deployed after loader stages such as Claimloader and has also served as the basis for later derivative implants including MINIRECON.
ToneShell is typically executed entirely in memory as shellcode or delivered through DLL side-loading chains that abuse legitimate signed executables. Observed delivery patterns include spearphishing lures carrying archives or documents that lead to sideloaded malicious DLLs, as well as password-protected archives linked from decoy documents. The malware has been launched through callback-based shellcode execution and has also abused regsvr32 for execution. Multiple campaigns used legitimate applications to side-load malicious DLL components that decrypt and execute ToneShell in memory.
Its core functionality is consistent with a backdoor used for post-compromise control. Documented capabilities include periodic beaconing, resilient command-and-control communications, file upload or transfer, and interactive reverse shell access. Newer variants adopted WinHTTP-based secure WebSocket communications over TLS, added proxy awareness, and improved evasion through junk code, obfuscated string construction, and other anti-analysis measures. Some variants support multiple concurrent reverse shells and maintain keepalive traffic to sustain operator access.
ToneShell has also demonstrated defense-evasion behavior. It has checked for security software, abused legitimate Windows utilities for execution, and used DLL side-loading to blend into normal application behavior. Reporting on related HoneyMyte activity indicates that kernel-mode enhancements comparable to those seen with ToneShell were later expanded in other tooling, underscoring the family’s role in the actor’s broader progression toward stealthier post-exploitation implants.
Overall, ToneShell is a mature espionage backdoor family within the Mustang Panda ecosystem, notable for in-memory execution, sideloading-based deployment, evolving command-and-control tradecraft, and interactive operator support for reconnaissance, file theft, and sustained access on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign relied on the use of Claimloader malware, lure documents, and the Toneshell backdoor.
The campaign relied on the use of Claimloader malware, lure documents, and the Toneshell backdoor.
We found connections between ShadowSyndicate infrastructure and Amos Stealer infrastructure (moderate confidence) as well as though with lower confidence, with ToneShell backdoor
We found connections between ShadowSyndicate infrastructure and Amos Stealer infrastructure (moderate confidence) as well as though with lower confidence, with ToneShell backdoor
Family Custom Mustang Panda beacon (cs_djb2 fork – structurally CS-compatible but operator-modified) ... Article Link: [QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis
This includes an updated Toneshell variant evading detections and supporting several new features... One of the variants evading VirusTotal detections is the latest update "Toneshell9".
35 distinct techniques documented for this family, organized by ATT&CK tactic.
In May 2026, X-Force uncovered an email with the subject ‘China BG’ delivered to recipients within the Indian government. The email includes a PDF attachment titled, “Hydropower Cooperation Project Study.pdf” imitating Nepal’s Ministry of Foreign Affairs (MoFA).
First-run path : drop itself into C:\ProgramData\Dexpot\ (exact filename detailed in companion report), register scheduled task MediumNetMonIt , exit.
The capabilities of ToneShell are designed for cyberespionage that includes: Executing commands
Across both incidents, operators conducted reconnaissance, harvested credentials and deployed malware... systeminfo, whoami, net group, netstat, tasklist executed in rapid succession.
It retains Toneshell fingerprints such as PEB-walking to locate kernel32.dll and the family’s 13131313 API-hashing multiplier... using the native WinHTTP API
Calls EnumSystemLocalesA() with the in-memory blob as the callback target
Victims will receive and interact with a decoy document containing a Google Drive link and a corresponding password instead of an archive download link embedded in the email.
The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service... The driver enhances the malware’s stealth by hiding the CoolClient process, protecting related files and registry entries, and preventing them from being inspected or modified.
Defense Evasion T1027 Obfuscated Files cs_djb2 hash resolution, interleaved char-by-char URL/User-Agent construction, decoded-by-callback shellcode delivery
Defense Evasion T1027.002 Software Packing Position-independent shellcode – no PE headers, opaque to static AV
the fake .docx files have XOR-encrypted content to prevent detection
Using ASCII or decoded Base64 strings that represent UUID strings. Calling UuidFromStringA to convert the decoded UUIDs to binary data, each of which represents 16 bytes of shellcode.
The loaders subsequently execute embedded shellcode using the EnumSystemLocalesA API as a callback mechanism.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory.
MW_CMD_OPEN_SHELL (5) C2 -> beacon cmd.exe stdout stream via pipe drain thread
The capabilities of ToneShell are designed for cyberespionage that includes: ... File system interaction
Command and Control T1008 Fallback Channels PATH B: HTTP -> proxy -> WebSocket fallback if direct connection fails
For two IPs of the ShadowSyndicate infrastructure, we found Cobalt strike beacons at the same timeframe that were linked to the Citrix bleed exploit attack campaign where Lockbit ransomware was chiefly deployed by affiliates.
Earlier variants relied on custom socket-based communications, while version 10 transitions to secure WebSocket communications using WinHTTP over TLS.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
The first request that the binary sends is: hxxps://datasmetrics.]com/files/Loader_TM.dll that should deliver a second stage.
160 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
91 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison point for kernel-mode stealth enhancements similar to those seen with COOLCLIENT.
In-memory 32-bit backdoor used by ITG27 that communicates over secure WebSockets (WSS/TLS) via WinHTTP and supports keepalive, file upload, and interactive reverse shell commands.
A backdoor used by ITG27 that provides reverse-shell access, session management, file upload/drop capability, and WebSocket-over-TLS C2 in version 10. In the observed campaign it was delivered by Claimloader and used for hands-on-keyboard post-exploitation.
Referenced as a malware/backdoor whose kernel-mode enhancements are comparable to those seen in the latest CoolClient variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.