The China-linked Mustang Panda APT has been using a kernel-mode rootkit in attacks leading to ToneShell backdoor deployments.
The platform attributed the incident to a third-party login provider, which several users speculated was Magic Labs, a ...