Mustang Panda Hits India and S. Korea with Updated LOTUSLITE Backdoor
ID: 623d27c0-ffef-57a2-9849-b66e3699fb61
STIX ID: report--623d27c0-ffef-57a2-9849-b66e3699fb61
Feed Name: HackRead
**Executive Summary:** Mustang Panda expanded espionage efforts in March 2026 targeting HDFC Bank employees in India and South Korean diplomacy/policy circles by delivering a LOTUSLITE v1.1 backdoor via malicious CHM files and fake Google Drive invitations, leveraging DLL sideloading into signed Microsoft executables, rotating internal 'magic' values and command flags, and reusing Gleeze infrastructure; multiple IOCs (filenames, domains, and an impersonating email) link the activity to the group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
