logo

New “LOTUSLITE” Backdoor Targets U.S. Government in Suspected Mustang Panda Campaign

ID: aeacbbed-07b1-5bcc-8f31-102ed10f9af9

STIX ID: report--aeacbbed-07b1-5bcc-8f31-102ed10f9af9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Acronis TRU reports a targeted espionage campaign delivering a custom C++ backdoor named LOTUSLITE via spear-phishing ZIP attachments that sideload a malicious kugou.dll alongside a signed Tencent music player executable; researchers link the operation with moderate confidence to Mustang Panda, noting persistence via a Run registry entry, C2 communications that mimic legitimate web traffic, and hard-coded network indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.