Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
ID: db37b253-8f2a-5bd1-a81e-a1549aeee9ad
STIX ID: report--db37b253-8f2a-5bd1-a81e-a1549aeee9ad
Feed Name: The Hacker News
Acronis researchers observed an active espionage campaign deploying an updated LOTUSLITE backdoor via malicious CHM files that use JavaScript droppers and DLL side‑loading to run dnx.onecore.dll; the implant communicates over dynamic DNS/HTTPS (editor.gleeze.com) to enable remote shell, file operations, and data exfiltration. The campaign has pivoted to target India's banking sector (lures referencing HDFC Bank) while also impacting South Korean and U.S. policy/diplomatic entities, and is attributed with medium confidence to the Mustang Panda group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
