logo

The Lotus Evolves: Mustang Panda Targets Indian Banks in a New Espionage Pivot

ID: 17d67ca7-e998-5449-a44c-525ae92e17ee

STIX ID: report--17d67ca7-e998-5449-a44c-525ae92e17ee

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

Acronis TRU reports that Mustang Panda has shifted from government-focused operations to a targeted campaign against India’s banking sector, deploying an evolved LOTUSLITE backdoor via DLL sideloading. The implant provides remote shell access, file operations, and persistent session management while communicating with dynamic DNS-based C2 over encrypted HTTPS; researchers attribute the activity to Mustang Panda with moderate confidence and note targeted lures and masqueraded banking software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.