QReverse is a backdoor/remote access trojan used in espionage operations attributed to the China-linked HoneyMyte threat group, also known as Mustang Panda and Bronze President. The provided content identifies QReverse as part of HoneyMyte’s toolset alongside ToneShell, PlugX, and CoolClient, and notes threat-hunting focused on HoneyMyte’s QReverse backdoor. QReverse has been described as being dropped by TONESHELL/ToneShell as an additional payload. Its documented capabilities include remote shell access, file management, screenshot capture, and information gathering. The broader campaigns described primarily targeted government entities across Asia and Europe, with Southeast Asia especially affected. No specific infection vector, persistence mechanism, or standalone indicators of compromise are directly provided for QReverse beyond its delivery as an additional payload by TONESHELL in HoneyMyte intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan providing remote shell, file management, screenshot capture, and information gathering capabilities; delivered as a payload dropped by TONESHELL in the described activity.
Backdoor used by HoneyMyte; referenced as an investigation pivot that led to discovery of an additional browser credential-stealer variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.