Netskope Threat Labs

TONESHELL

ATP Sandbox Adv. HeuristicsAV

TONESHELL is a detection name for shell based malware that gives operators command execution and foothold maintenance on compromised systems. Detections under this name indicate an implant used in targeted campaigns, delivered through staged chains that favor quiet persistence over noisy exploitation. Researchers have tied the family to sophisticated intrusions, so analysts should treat detections as evidence of a serious compromise in progress.

First seen
November 2022
Last seen
October 2026
ToneShellToneshell

43 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1010Application Window Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1087Account Discovery
  • T1518Software Discovery
  • T1680Local Storage Discovery

TA0009 Collection

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Gen:Variant.ToneShell.1
Trojan.ToneShell.A
Win32.Backdoor.Toneshell
Win32.Trojan.Toneshell
Win32.Trojan.ToneShell
Win64.Trojan.ToneShell