logo

Mastang Panda Uses Venezuela News to Spread LOTUSLITE Malware

ID: ebb65f3a-c92c-53b6-a4cb-7c40392d56a6

STIX ID: report--ebb65f3a-c92c-53b6-a4cb-7c40392d56a6

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Acronis Threat Research found a targeted spear‑phishing campaign using Venezuela news lures and a renamed music player to DLL‑sideload a backdoor called LOTUSLITE; the malware enables remote control and data theft, sends exfiltrated data to 172.81.60.97, and is attributed with moderate confidence to the China‑linked Mustang Panda group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.