Contact

Toneshell Backdoor Used to Target Attendees of the IISS Defence Summit

NetmanageIT OpenCTI - opencti.netmanageit.com

Toneshell Backdoor Used to Target Attendees of the IISS Defence Summit



SUMMARY :

A cyber espionage campaign using the ToneShell backdoor, associated with Mustang Panda, has been detected targeting attendees of the 2024 IISS Defence Summit in Prague. The attack utilizes a malicious PIF file masquerading as summit documents, which drops SFFWallpaperCore.exe and libemb.dll. The malware establishes persistence through registry run keys and scheduled tasks, communicating with a C2 server in Hong Kong using raw TCP mimicking TLS. The campaign highlights the intersection of cyber espionage and international strategy, aiming to infiltrate sensitive defense discussions. Analysis revealed connections to previously reported APT-Q-27 activities and potential links to other infrastructure through shared RDP certificates.

OPENCTI LABELS :

toneshell,phishing,gh0st rat,dll sideloading,pif file


Open in NetmanageIT OpenCTI Public Instance with below link!


Use public read only username and password on login page.

NOTE : Use Public READ only user credentials on login page banner.


Toneshell Backdoor Used to Target Attendees of the IISS Defence Summit