Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors
ID: 91a3b13f-0432-50f9-a8ec-e6269b2f1298
STIX ID: report--91a3b13f-0432-50f9-a8ec-e6269b2f1298
Feed Name: ThreatCluster
Threat Score
Mustang Panda conducted two espionage campaigns in June 2026 against Indian hydropower and government targets, using Taiwan-related lure documents to deliver SHARDLOADER, MINIRECON, and ZOHOMURK via DLL sideloading and weaponized archives. Acronis attributes the activity to Mustang Panda (linked to China); the campaigns show reuse of tools and knowledge of India's software compliance environment, signaling a persistent, capable threat to critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
