Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 23:36:19 UTC Home > List all groups > List all tools > List all groups using tool TONEINS Tool: TONEINS Names TONEINS Category Malware Type Dropper, Loader Description (Trend Micro) Trojan.Win32.TONEINS is the installer for TONESHELL backdoors. The installer drops the TONESHELL malware to the %PUBLIC% folder and establishes the persistence for it. TONEINS malware usually comes in the lure archives, and in most cases, the name of the TONEINS DLL is libcef.dll. The malicious routine is triggered via calling its export function cef_api_hash. Information Last change to this tool card: 19 November 2022 Download this tool card in JSON format All groups using tool TONEINS Changed Name Country Observed APT groups   CeranaKeeper 2022-2023     Mustang Panda, Bronze President 2012-Jun 2025   2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7259ece1-262f-4880-baa1-8a4e0d0f6752 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7259ece1-262f-4880-baa1-8a4e0d0f6752 Page 1 of 1