Description
TONESHELL is a detection name for shell based malware that gives operators command execution and foothold maintenance on compromised systems. Detections under this name indicate an implant used in targeted campaigns, delivered through staged chains that favor quiet persistence over noisy exploitation. Researchers have tied the family to sophisticated intrusions, so analysts should treat detections as evidence of a serious compromise in progress.
Stats
- First seen
- November 2022
- Last seen
- October 2026
Also known as
ToneShellToneshell
MITRE ATT&CK techniques
43 techniques across 7 tactics.
TA0002 Execution
TA0003 Persistence
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1036Masquerading
- T1055Process Injection
- T1055.001Dynamic-link Library Injection
- T1070Indicator Removal
- T1070.004File Deletion
- T1134Access Token Manipulation
- T1134.002Create Process with Token
- T1140Deobfuscate/Decode Files or Information
- T1205Traffic Signaling
- T1218System Binary Proxy Execution
- T1480Execution Guardrails
- T1480Execution Guardrails
- T1497Virtualization/Sandbox Evasion
- T1497.002User Activity Based Checks
- T1574Hijack Execution Flow
- T1574.001DLL
- T1622Debugger Evasion
- T1678Delay Execution
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.ToneShell.1 |
| Trojan.ToneShell.A |
| Win32.Backdoor.Toneshell |
| Win32.Trojan.Toneshell |
| Win32.Trojan.ToneShell |
| Win64.Trojan.ToneShell |
