logo

Middle East Conflict Fuels Cyber Attacks

ID: f8665599-0341-5f72-80dd-c10f59780e6b

STIX ID: report--f8665599-0341-5f72-80dd-c10f59780e6b

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-05-01

...
...

ThreatLabz analyzed a Mustang Panda campaign that delivered the LOTUSLITE backdoor using a malicious DLL (libmemobook.dll) sideloaded by a renamed KuGou executable themed around Iran conflict. The downloader enforces installation to C:\ProgramData (creating Run keys for persistence), decrypts and executes embedded shellcode that fetches WebFeatures.exe and kugou.dll from a compromised domain (e-kflower.com), and the next-stage DLLs exhibit code overlap with previously documented LOTUSLITE implants (C2: 172.81.60.97).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.