<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Toneshell on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/tags/toneshell/</link>
    <description>Recent content in Toneshell on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 24 Feb 2026 06:03:02 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/tags/toneshell/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor</title>
      <link>https://cluster-site.onrender.com/posts/the-honeymyte-apt-evolves-with-a-kernel-mode-rootkit-and-a-toneshell-backdoor/</link>
      <pubDate>Mon, 29 Dec 2025 10:00:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-honeymyte-apt-evolves-with-a-kernel-mode-rootkit-and-a-toneshell-backdoor/</guid>
      <description>• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi</description>
    </item>
  </channel>
</rss>
