Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
ID: ab9eb082-ccd7-5ebf-818e-35fe41f74a2d
STIX ID: report--ab9eb082-ccd7-5ebf-818e-35fe41f74a2d
Feed Name: The Hacker News
Acronis attributes two active Mustang Panda campaigns (June 12–22, 2026) targeting Indian government and hydropower entities; attackers used spear-phishing ZIPs that sideload malicious DLLs to deploy SHARDLOADER (loader), MINIRECON (Toneshell-derived backdoor over WebSocket/HTTPS) and ZOHOMURK, which abuses Zoho WorkDrive with hardcoded OAuth tokens to receive commands and exfiltrate data. The activity included actual compromises of Indian government machines, reused/insecure operational practices (hardcoded tokens, plaintext identifiers, reused infrastructure), and published IOCs and hunting tips for detection and cleanup.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
