TONESHELL

S1239

Malware.View on attack.mitre.org

About this malware

TONESHELL is a custom backdoor that has been used since at least Q1 2021. TONESHELL malware has previously been leveraged by Chinese affiliated actors identified as Mustang Panda.

Techniques used43

Procedure examples43

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3.

T1010
Application Window Discovery

TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1027.001
Binary Padding

TONESHELL has used randomized padding to obfuscate payloads.

T1027.007
Dynamic API Resolution

TONESHELL has utilized a modified DJB2 algorithm to resolve APIs.

T1027.012
LNK Icon Smuggling

TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1033
System Owner/User Discovery

TONESHELL has obtained the username from an infected host.

T1036.004
Masquerade Task or Service

TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service).

T1036.005
Match Legitimate Resource Name or Location

TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.

T1047
Windows Management Instrumentation

TONESHELL has used WMI queries to gather information from the system.

T1053.005
Scheduled Task

TONESHELL has created scheduled tasks to maintain persistence.

T1055.001
Dynamic-link Library Injection

TONESHELL has used DLL injection to execute payloads received from the C2 server.

T1056.001
Keylogging

TONESHELL has capabilities to conduct keylogging.

T1057
Process Discovery

TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe.

T1059.003
Windows Command Shell

TONESHELL has created a reverse shell using `cmd.exe`.

T1070.004
File Deletion

TONESHELL has deleted payload files received from the C2 server.

View all 43 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. ATTACKIQ MUSTANG PANDA TONESHELL March 2023 Open source
    Ken Towne, Francis Guibernau. (2023, March 23). Emulating the Politically Motivated Chinese APT Mustang Panda. Retrieved September 10, 2025.
  2. Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023 Open source
    Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.
  3. Zscaler Open source
    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.