LOTUSLITE: Targeted espionage leveraging geopolitical themes
ID: 9a6feea2-9789-5731-89f8-2db59db88885
STIX ID: report--9a6feea2-9789-5731-89f8-2db59db88885
Feed Name: TRU Security by Acronis
Threat Score
**Acronis TRU observed a targeted spear-phishing campaign delivering a DLL sideloaded backdoor named LOTUSLITE to U.S. government and policy-related entities; the report details the loader–DLL delivery, implant capabilities (remote shell, file ops, beaconing), persistence, hard-coded C2 (172.81.60.97), IoCs, and a moderate-confidence behavioral attribution to Mustang Panda.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
