New “LOTUSLITE” Backdoor Targets U.S. Government in Suspected Mustang Panda Campaign
ID: aeacbbed-07b1-5bcc-8f31-102ed10f9af9
STIX ID: report--aeacbbed-07b1-5bcc-8f31-102ed10f9af9
Feed Name: securityonline.info
Threat Score
Acronis TRU reports a targeted espionage campaign delivering a custom C++ backdoor named LOTUSLITE via spear-phishing ZIP attachments that sideload a malicious kugou.dll alongside a signed Tencent music player executable; researchers link the operation with moderate confidence to Mustang Panda, noting persistence via a Run registry entry, C2 communications that mimic legitimate web traffic, and hard-coded network indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
