logo

Chinese spies used Maduro's capture as a lure to phish US govt agencies

ID: d24bbfbf-02f4-5fd3-bae3-cd853ab4d7e3

STIX ID: report--d24bbfbf-02f4-5fd3-bae3-cd853ab4d7e3

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Acronis Threat Research Unit uncovered a targeted phishing campaign, attributed with moderate confidence to Beijing-backed Mustang Panda, that used a geopolitical lure about US plans for Venezuela to deliver a DLL-sideloaded backdoor named Lotuslite hidden alongside a renamed legitimate Kugou launcher; the C++ implant establishes persistence, beaconing to hard-coded IP-based C2 and enables data theft from infected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.