logo

Attackers Use Microsoft-Signed Binary To Deploy LOTUSLITE In India-Focused Cyber Campaign

ID: 125617eb-c13b-5ee1-a13e-9f1998072a72

STIX ID: report--125617eb-c13b-5ee1-a13e-9f1998072a72

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Varshini

...
...

**Acronis TRU reports an active Mustang Panda-linked campaign targeting Indian banks using spear-phishing CHM files that drop a JavaScript loader and leverage DLL sideloading of a Microsoft-signed binary to deploy an updated LOTUSLITE backdoor; the malware includes new exports and a banking-themed entrypoint while leaving operational artifacts that aided attribution.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.