ToneDisk is a USB worm framework associated with the China-aligned threat actor Mustang Panda, also tracked as HoneyMyte and Hive0154. It is also referred to as WispRider. Reporting describes ToneDisk as part of the broader ToneShell malware family and notes multiple major versions, including ToneDisk A, B, and C. IBM X-Force identified strong code and tradecraft overlaps between ToneDisk—especially ToneDisk A—and the newer SnakeDisk USB worm.
ToneDisk is used to propagate via removable media and has been repeatedly observed on systems compromised in long-running espionage operations. It is commonly mentioned alongside other Mustang Panda tooling including ToneShell and PlugX, and investigators found many affected victims had prior infections involving the ToneDisk USB worm before later intrusion waves. The malware has been linked to campaigns targeting government and other entities in Southeast and East Asia, with multiple reports specifically referencing victims in Thailand and Myanmar and broader targeting of Thai entities in 2025.
The content directly states that ToneDisk is a USB worm and that, in recent Mustang Panda activity, a related USB worm framework was used to distribute the Yokai backdoor through removable devices. ToneDisk is therefore best characterized as a removable-media propagation component within Mustang Panda/HoneyMyte intrusion chains, supporting persistence and lateral spread into environments where USB-borne infection is effective, including potentially segmented or air-gapped networks. No standalone ToneDisk-specific hashes or network indicators are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
X-Force analysis also revealed strong overlaps between SnakeDisk and Tonedisk... So far, there have been 3 major Tonedisk versions (A, B and C) identified.
1 distinct technique documented for this family, organized by ATT&CK tactic.
The worm displays code overlaps with Tonedisk and is able to detect new and existing USB devices, which it weaponizes as a means of propagation... SnakeDisk begins to loop through all possible drive letters from A-Z... For newly connected devices, a new thread is launched to infect the drive.
The worm displays code overlaps with Tonedisk and is able to detect new and existing USB devices, which it weaponizes as a means of propagation... SnakeDisk begins to loop through all possible drive letters from A-Z... For newly connected devices, a new thread is launched to infect the drive.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
USB-propagating worm referenced as an additional payload dropped in the described campaigns; specific behavior beyond being a USB worm is not detailed.
A USB-propagated worm used in targeted attacks by APT groups.
A USB worm associated with Chinese APT operations, used for spreading malware and maintaining persistence in targeted environments.
A USB-propagating worm mentioned as an associated tool present on compromised hosts in the same intrusion set.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.