MINIRECON is a Windows backdoor associated with the China-linked espionage group Mustang Panda. It is a reworked variant of the TONESHELL malware family and has been observed in 2026 espionage operations targeting Indian government entities and the hydropower sector. The malware was deployed through a DLL sideloading chain involving the SHARDLOADER loader and legitimate signed executables, delivered via spearphishing archives using politically themed lures.
MINIRECON preserves multiple implementation traits associated with TONESHELL, including PEB walking for API resolution and hashed API lookup, indicating lineage from that family rather than an unrelated implant. Its command-and-control channel uses WebSocket communications over HTTPS through the native WinHTTP API, and it disables certificate validation to facilitate connections to attacker-controlled infrastructure, including environments using self-signed certificates. It also includes proxy fallback logic to enumerate local proxy settings when direct outbound connectivity fails.
Functionally, MINIRECON supports remote command execution, reverse shell access, file upload and download, and drop-and-execute tasking, making it suitable for interactive post-compromise operations. Operators were observed using infected systems for live reconnaissance and attempting anti-analysis or disruption actions after detecting sandboxed environments. The malware fits Mustang Panda’s long-running espionage tradecraft, which emphasizes stealthy persistence, abuse of legitimate software for sideloading, and long-term intelligence collection against government, diplomatic, military, and critical infrastructure targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Campaign I (hydropower) decrypts and launches MINIRECON, a variant of the Toneshell8 implant.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp...
After identifying the environment as an analyst sandbox, the operator attempted to disrupt analysis by deleting tools and corrupting multiple files on the host... the implant removes it from WorkDrive by sending a PATCH request... which moves the file to trash.
After identifying the environment as an analyst sandbox, the operator attempted to disrupt analysis by deleting tools and corrupting multiple files on the host.
Acronis observed the operator conducting live reconnaissance on infected hosts
After identifying the environment as an analyst sandbox, the operator attempted to disrupt analysis by deleting tools and corrupting multiple files on the host.
ZOHOMURK is the most unusual piece of this operation. It carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a covert command channel.
MINIRECON ... upgrades C2 to a WebSocket connection over HTTPS using the native WinHTTP API
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TONESHELL-related implant variant launched by SHARDLOADER that uses WebSocket-over-HTTPS C2, disables certificate validation, and includes proxy fallback to blend into enterprise networks.
Reconnaissance malware/tool used by Mustang Panda in campaigns abusing Zoho WorkDrive for C2 and exfiltration.
A newly observed implant/backdoor used after SHARDLOADER execution; it is described as a reworked Toneshell variant that uses WebSocket over HTTPS for covert communications.
Backdoor implant described as a reworked Toneshell variant that communicates over HTTPS using WebSocket beaconing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.