Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign
ID: 59fa42af-3ae3-5873-bb9c-bbbd8cff5ace
STIX ID: report--59fa42af-3ae3-5873-bb9c-bbbd8cff5ace
Feed Name: cybersecurityNews.com
Threat Score
A state-linked threat actor (assessed as Mustang Panda) conducted a stealthy espionage campaign targeting India's banking sector by delivering a new LOTUSLITE backdoor via DLL sideloading of a legitimate Microsoft-signed executable; the implant supports remote shell, file operations and session management and communicates with a dynamic DNS-based C2 over HTTPS, with the same infrastructure observed in parallel Korea-focused activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
