logo

Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics

ID: 8260a4e2-8c2c-5282-96b6-e0acfd0bab99

STIX ID: report--8260a4e2-8c2c-5282-96b6-e0acfd0bab99

Feed Name: TRU Security by Acronis

Threat Score
85/100

Date Published: 2026-04-21

Date Updated: 2026-07-24

...
...

This Acronis TRU report documents a LOTUSLITE v1.1 backdoor variant delivered via DLL sideloading of legitimate Microsoft-signed binaries and JavaScript loaders, targeting India's banking sector (HDFC-themed) and diplomatic/policy targets; it details delivery, execution, C2 (editor.gleeze.com), persistence, API-resolution evasion, code lineage to LOTUSLITE, moderate-confidence attribution to Mustang Panda, and provides IoCs (hashes, domains, mutexes, paths) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.