The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi

Cybersecurity · December 29, 2025 (updated February 24, 2026) · 2 min · 278 words