logo

Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign

ID: 59fa42af-3ae3-5873-bb9c-bbbd8cff5ace

STIX ID: report--59fa42af-3ae3-5873-bb9c-bbbd8cff5ace

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Tushar Subhra Dutta

...
...

A state-linked threat actor (assessed as Mustang Panda) conducted a stealthy espionage campaign targeting India's banking sector by delivering a new LOTUSLITE backdoor via DLL sideloading of a legitimate Microsoft-signed executable; the implant supports remote shell, file operations and session management and communicates with a dynamic DNS-based C2 over HTTPS, with the same infrastructure observed in parallel Korea-focused activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.