A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
See the CI worfklow for the list of distribution versions actively tested in each pull request. If you or your organization gets value out of this collection, I would very much appreciate one-time or ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results