The China-linked Mustang Panda APT has been using a kernel-mode rootkit in attacks leading to ToneShell backdoor deployments.
Researchers uncovered 27 malicious npm packages used over five months to host phishing pages that steal credentials from ...