Full Report
Kaspersky discloses a 2025 HoneyMyte (aka Mustang Panda or Bronze President) APT campaign, which uses a kernel-mode rootkit to deliver and protect a ToneShell backdoor.
Analysis Summary
# Threat Actor: HoneyMyte (APT)
## Attribution & Identity
**Actor Identification:** Threat actor group tracked as HoneyMyte.
**Known Aliases:** Mustang Panda, Bronze President.
**Known Associations:** Described as an APT (Advanced Persistent Threat).
## Activity Summary
The article reports on a **2025** HoneyMyte campaign. This campaign is characterized by the deployment of a kernel-mode rootkit specifically designed to deliver and protect its primary backdoor payload, ToneShell.
## Tactics, Techniques & Procedures
- **Kernel-Mode Rootkit Usage:** Deploying a rootkit functionality operating at the kernel level.
- **Payload Protection:** Using the rootkit to conceal and secure the ToneShell backdoor.
- **Delivery Mechanism:** Using the rootkit/backdoor combination to maintain persistence and hide activities.
- **Specific Malware:** ToneShell backdoor.
- **MITRE ATT&CK IDs:** Not explicitly mentioned in the provided context snippet.
## Targeting
- **Sectors:** Not specified in the provided context, but APTs typically target government, defense, high-tech industries, and critical infrastructure.
- **Geography:** Not specified in the provided context.
- **Victims:** Not specified in the provided context.
## Tools & Infrastructure
- **Malware Families Used:** ToneShell (backdoor), Kernel-mode rootkit.
- **Infrastructure:** No specific C2 infrastructure (URLs/IPs) was provided in the context snippet.
## Implications
The use of a sophisticated kernel-mode rootkit signifies a high level of technical capability within the HoneyMyte group. Kernel-level persistence makes detection and remediation significantly more challenging for standard security solutions, indicating the actor prioritizes deep system access and long-term espionage.
## Mitigations
- Focus on advanced endpoint detection and response (EDR) capable of kernel-level monitoring.
- Implement robust vulnerability management to prevent the initial entry vector used by the actor.
- Proactive monitoring for signs of rootkit activity or suspicious kernel module loading.