logo

LOTUSLITE: Targeted espionage leveraging geopolitical themes

ID: 9a6feea2-9789-5731-89f8-2db59db88885

STIX ID: report--9a6feea2-9789-5731-89f8-2db59db88885

Feed Name: TRU Security by Acronis

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-07-24

...
...

**Acronis TRU observed a targeted spear-phishing campaign delivering a DLL sideloaded backdoor named LOTUSLITE to U.S. government and policy-related entities; the report details the loader–DLL delivery, implant capabilities (remote shell, file ops, beaconing), persistence, hard-coded C2 (172.81.60.97), IoCs, and a moderate-confidence behavioral attribution to Mustang Panda.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.