A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
Once the project was ready, I fed the entire codebase into NotebookLM. I uploaded all the .py files as plain text files, ...