logo

Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON

ID: bfa1593e-3821-51ee-8273-b63271073207

STIX ID: report--bfa1593e-3821-51ee-8273-b63271073207

Feed Name: TRU Security by Acronis

Threat Score
90/100

Date Published: 2026-06-28

Date Updated: 2026-07-24

...
...

Acronis TRU documents two Mustang Panda espionage campaigns against Indian government and hydropower targets that deliver DLL-sideloading loaders (SHARDLOADER) which deploy two implants: MINIRECON (a WebSocket-enabled ToneShell-derived backdoor) and ZOHOMURK (a novel implant that abuses Zoho WorkDrive for C2 and exfiltration). The report includes detailed technical analysis, persistence and anti-analysis techniques, infrastructure and IOCs (file hashes, domains, IPs), observed active compromises, and mitigation/hunting guidance shared with CERT-In.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.