Attackers Use Microsoft-Signed Binary To Deploy LOTUSLITE In India-Focused Cyber Campaign
ID: 125617eb-c13b-5ee1-a13e-9f1998072a72
STIX ID: report--125617eb-c13b-5ee1-a13e-9f1998072a72
Feed Name: Cyber Press
Threat Score
**Acronis TRU reports an active Mustang Panda-linked campaign targeting Indian banks using spear-phishing CHM files that drop a JavaScript loader and leverage DLL sideloading of a Microsoft-signed binary to deploy an updated LOTUSLITE backdoor; the malware includes new exports and a banking-themed entrypoint while leaving operational artifacts that aided attribution.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
