Close Menu
    What's Hot

    Netherlands vs. Morocco prediction, odds, betting line, time: 2026 World Cup Round of 32 picks

    Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

    Buying a Mattress in 2026? We Tested 100+ and These Were the Standouts

    Facebook X (Twitter) Instagram
    Trending
    • Netherlands vs. Morocco prediction, odds, betting line, time: 2026 World Cup Round of 32 picks
    • Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
    • Buying a Mattress in 2026? We Tested 100+ and These Were the Standouts
    • Director Who Defrauded Netflix Gets 30-Month Prison Term
    • What Might The Fed Do With Rates After June’s Job Report (NYSEARCA:IWM)
    • Gregg Berhalter in tears after son Sebastian’s World Cup goal
    • Taking stock of the AFC North: ‘It’s a transition year for the division’
    • AI couldn’t fix quality problems. So Ford rehired its most experienced engineers
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

    adminBy adminJune 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 29, 2026Threat Intelligence / Malware

    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

    The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel.

    Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with CERT-In on notification and cleanup.

    The malware abuses Zoho WorkDrive, a cloud storage platform common in India’s government sector, to pass commands and exfiltrate data. That is the whole idea: the traffic looks like ordinary cloud activity, so it hides inside the network it is stealing from.

    Cybersecurity

    Acronis names three new tools.

    • SHARDLOADER is a loader that runs by sideloading a malicious DLL through a legitimately signed binary, a Solid PDF Creator executable in one campaign, and a Citrix Receiver binary in the other. It deploys one of two implants.
    • MINIRECON is a reworked variant of the Toneshell backdoor documented by IBM X-Force, now beaconing over a WebSocket connection on HTTPS.
    • ZOHOMURK is the novel piece: it carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a dead drop, reading commands from an inbox folder and writing stolen output to an outbox.

    Both campaigns arrive as ZIP archives with the malicious DLL marked hidden. Acronis believes they were delivered by spear-phishing. The lures fit the targets: one themed around a hydropower cooperation proposal, the other around a memorandum of understanding between Indian and Taiwanese institutions.

    Per Acronis, the goal is intelligence on India’s hydropower plans and its defense ties with Taiwan. Acronis attributes the activity to Mustang Panda with high confidence.

    The report includes the reused Solid PDF Creator sideloading chain, code overlap with Toneshell, command servers sitting in the same network block as infrastructure IBM X-Force tied to the group, and a recurring typo, RunOnece, carried across multiple implants.

    Operational security was thin. Hardcoded tokens, plaintext identifiers, and reused infrastructure all helped analysts pin it down. Active beaconing ran from June 12 to June 22, 2026.

    Cybersecurity

    This continues a steady push against Indian targets. In April, Acronis tied the group’s LOTUSLITE backdoor to attacks on India’s banking sector and South Korean policy circles, also staged through a legitimate cloud service. The broader China-linked interest in India’s power sector goes back further: the 2021 RedEcho campaign targeted the country’s electricity grid with ShadowPad.

    There is no patch to apply. The defense is catching the delivery and the cloud abuse. Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser processes.

    Government and energy organizations, especially those tied to cross-border deals likely to interest Beijing, should watch for geopolitical lures and sideloading from signed binaries. And flag any endpoint process calling cloud APIs that it has no reason to touch.

    Attacks channel Command government Indian Mustang Panda WorkDrive Zoho
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhat the U.S. Owes Venezuela
    Next Article Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs
    admin
    • Website

    Related Posts

    Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

    June 30, 2026

    Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

    June 29, 2026

    Israeli attacks kill four men and a boy in Gaza and a teenager in West Bank | Israel-Palestine conflict News

    June 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Netherlands vs. Morocco prediction, odds, betting line, time: 2026 World Cup Round of 32 picks

    Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

    Buying a Mattress in 2026? We Tested 100+ and These Were the Standouts

    Director Who Defrauded Netflix Gets 30-Month Prison Term

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by