logo

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

ID: ab9eb082-ccd7-5ebf-818e-35fe41f74a2d

STIX ID: report--ab9eb082-ccd7-5ebf-818e-35fe41f74a2d

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-29

Date Updated: 2026-07-01

Author: [email protected] (The Hacker News)

...
...

Acronis attributes two active Mustang Panda campaigns (June 12–22, 2026) targeting Indian government and hydropower entities; attackers used spear-phishing ZIPs that sideload malicious DLLs to deploy SHARDLOADER (loader), MINIRECON (Toneshell-derived backdoor over WebSocket/HTTPS) and ZOHOMURK, which abuses Zoho WorkDrive with hardcoded OAuth tokens to receive commands and exfiltrate data. The activity included actual compromises of Indian government machines, reused/insecure operational practices (hardcoded tokens, plaintext identifiers, reused infrastructure), and published IOCs and hunting tips for detection and cleanup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.