Names | TONEINS | |
Category | Malware | |
Type | Dropper, Loader | |
Description | (Trend Micro) Trojan.Win32.TONEINS is the installer for TONESHELL backdoors. The installer drops the TONESHELL malware to the %PUBLIC% folder and establishes the persistence for it. TONEINS malware usually comes in the lure archives, and in most cases, the name of the TONEINS DLL is libcef.dll. The malicious routine is triggered via calling its export function cef_api_hash. | |
Information | <https://www.trendmicro.com/en_us/research/22/k/earth-preta-spear-phishing-governments-worldwide.html> |
Last change to this tool card: 19 November 2022
Download this tool card in JSON format
Previous: TONEDEAF 2.0
Next: TONESHELL
Changed | Name | Country | Observed | ||
APT groups | |||||
CeranaKeeper | 2022-2023 | ||||
Mustang Panda, Bronze President | 2012-Mar 2024 |
2 groups listed (2 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |