Hive0154 (Mustang Panda) Deploys Toneshell9 with Proxy-Blended C2 and SnakeDisk USB Worm Targeting Thailand Amid Cambodia Border Crisis

IBM X-Force published a threat intelligence report on IBM Security Intelligence documenting new July–August 2025 activity by Hive0154 (also tracked as Mustang Panda, Stately Taurus, Camaro Dragon, Twill Typhoon, Earth Preta) — a China-aligned threat actor targeting public and private organizations including think tanks, policy groups, and government agencies. New findings include Toneshell9 (evading VirusTotal detections), an updated Pubload variant, and a novel USB worm dubbed SnakeDisk that exclusively executes on Thailand-based IP addresses and drops the Yokai backdoor.

Toneshell8 (March 2025): Junk Code Anti-Analysis Techniques

Toneshell8 introduced junk code sections throughout its functions to evade static detection and hinder analysis. Three junk code patterns appear consistently: API calls that write random temporary files and immediately delete them; code that copies and loops through strings — initial samples used text copied from OpenAI's ChatGPT website; and random-interval Sleep calls. These junk sections appear within core functions including the API resolution routine, increasing function length and signature complexity without altering behavior.

Toneshell9 (July 2025): Proxy-Blended C2 and Dual Parallel Reverse Shells

Toneshell9 is the latest Toneshell variant, actively evading VirusTotal detections at time of discovery. It supports C2 communication through locally configured system proxies to blend beacon traffic with enterprise network patterns, and facilitates two reverse shells operating in parallel. Weaponized archives delivering Toneshell7 and Toneshell8 were mostly uploaded to VirusTotal from Singapore and Thailand. One campaign used a PDF lure impersonating the Myanmar Ministry of Foreign Affairs with a link to a Box Cloud Storage-hosted archive ("CallNotes.zip") discovered in September 2025. The updated Pubload variant adds decoy C2 server support and HTTP POST shellcode download capability alongside its existing raw TCP TLS-imitation protocol.

SnakeDisk USB Worm: Thailand-Only Execution, Yokai Backdoor, and Air-Gap Targeting

SnakeDisk is a USB worm discovered in mid-August 2025 that shares code overlaps with previous Hive0154 Tonedisk variants. A distinctive operational constraint: the worm checks the infected device's public IP address and only executes on Thailand-based machines. It detects both new and existing USB devices and weaponizes them for propagation. The analyzed sample drops the Yokai backdoor — previously documented by Netskope in December 2024 in campaigns targeting Thai officials — which establishes a reverse shell for arbitrary command execution. The Thailand-exclusive targeting aligns with the July–August 2025 Thailand-Cambodia border conflict: artillery exchanges and airstrikes began July 24, a US/Malaysia-brokered truce was reached July 28, and Cambodian accusations of a Thai assassination plot in early August preceded the worm's discovery, suggesting intelligence collection motivation. The IP-filtered execution design is consistent with attempting to penetrate air-gapped government network segments.

Read the full analysis on IntelFusions