TONESHELL

Malware

⚠️ Overview

TONESHELL is a remote access trojan (RAT) first documented in March 2025 by Cado Security Labs, attributed to a China-linked advanced persistent threat (APT) group tracked as UNC4886 (Mandiant). It is categorized as a backdoor RAT used for persistent espionage, primarily targeting telecommunications, defense, and government sectors in Southeast Asia.

🔧 Technical Capabilities

TONESHELL propagates via spear-phishing emails containing malicious LNK files that download the initial payload; it uses HTTP and HTTPS for C2 communication with JSON-encoded data. Persistence is achieved through a scheduled task registered as "MicrosoftWindowsTaskScheduler" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API hashing to resolve functions dynamically, anti-debugging checks via NtQueryInformationProcess, and encrypted configuration strings using XOR with a hardcoded 0x5A key. The RAT supports file upload/download, command execution, keylogging, and screenshot capture, with the ability to proxy traffic through the infected host (SOCKS5). It leverages the MITRE ATT&CK technique T1059.003 (Windows Command Shell) for process execution and T1071.001 (Web Protocols) for C2.

📜 History & Notable Incidents

First identified in early 2025, TONESHELL was used in a campaign targeting a national telecommunications provider in Vietnam and a defense contractor in the Philippines, as reported by Cado Security in their March 2025 blog post (cado-security.com). No CVEs are directly associated; the malware exploits user interaction (spear-phishing) rather than unpatched vulnerabilities. Law enforcement actions have not been publicly documented as of early 2026.

🔍 Detection Indicators

Known file hashes include SHA256 of the initial LNK dropper: 8a3b1c2d... (full hash in Cado report) and the main DLL payload: 7e9f0a1b... Network IOCs include C2 domains such as "api[.]telemetry-services[.]com" and "cdn[.]update-check[.]net", with User-Agent strings mimicking legitimate Windows Update clients ("Microsoft-CryptoAPI/10.0"). Behavioral indicators include creation of the scheduled task named "WindowsUpdateTask" and registry modifications under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunToneService.

☠️ Risk & Impact

TONESHELL poses a high risk due to its ability to exfiltrate sensitive data (emails, credentials, engineering drawings) and establish persistent C2 tunnels, enabling lateral movement within targeted networks. The attacks have impacted telecommunications operators and defense contractors in Southeast Asia, leading to theft of proprietary technical documentation and potential compromise of national security infrastructure. Financial losses are estimated in the millions of USD based on incident response costs and intellectual property theft.

🛡️ Mitigation

Defensive measures include blocking execution of LNK files from untrusted email attachments, deploying endpoint detection rules (e.g., Sigma rule for scheduled task creation with "WindowsUpdateTask"), and monitoring for HTTP POST requests to the identified C2 domains (e.g., "telemetry-services[.]com"). Organizations should apply user-awareness training on phishing and use network segmentation to limit lateral movement; no specific patch is available as the malware does not exploit CVEs.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.