logo

Mustang Panda Hits India and S. Korea with Updated LOTUSLITE Backdoor

ID: 623d27c0-ffef-57a2-9849-b66e3699fb61

STIX ID: report--623d27c0-ffef-57a2-9849-b66e3699fb61

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Mustang Panda expanded espionage efforts in March 2026 targeting HDFC Bank employees in India and South Korean diplomacy/policy circles by delivering a LOTUSLITE v1.1 backdoor via malicious CHM files and fake Google Drive invitations, leveraging DLL sideloading into signed Microsoft executables, rotating internal 'magic' values and command flags, and reusing Gleeze infrastructure; multiple IOCs (filenames, domains, and an impersonating email) link the activity to the group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.