Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft File Exploited in India-Focused Cyber Espionage

Microsoft File Exploited in India-Focused Cyber Espionage

Posted on April 22, 2026 By CWS

A state-backed cyber threat group has been identified executing a covert espionage operation against the Indian banking industry. This operation cleverly utilized a Microsoft-signed file to bypass security measures and deploy malware. The attack introduces a novel variant of the LOTUSLITE backdoor using DLL sideloading, a technique that leverages the inherent trust operating systems place in legitimate executables.

Stealthy Infiltration via Trusted Software

Unlike overt attack methods, the threat actor adopted a stealthy approach, seamlessly integrating malicious actions into normal system operations. The attack is initiated through a ZIP archive themed around the Indian financial sector. Within, a legitimate Microsoft executable, Microsoft_DNX.exe, serves as the unwitting host for the malicious DLL, which is loaded upon execution due to the executable’s lack of comprehensive file path verification.

As part of ongoing monitoring efforts, Acronis Threat Research Unit (TRU) analysts detected this LOTUSLITE variant. The malware’s links to Indian banking institutions became apparent during activity observed in March. TRU researchers highlighted the deliberate use of a Microsoft-signed executable as a means to bypass endpoint security checks, exploiting the general trust extended to Microsoft-signed files.

Persistent Cyber Threats and Espionage Goals

Once the LOTUSLITE backdoor is installed, it connects to a command-and-control (C2) server using dynamic DNS over HTTPS, allowing its traffic to blend with normal encrypted web communications. This backdoor grants the attacker remote shell access, file manipulation capabilities, and session management, ensuring a persistent presence on compromised systems. The backdoor’s design suggests a focus on espionage, prioritizing data gathering and sustained access over causing immediate disruptions.

The campaign shows connections to activities targeting Korea-related geopolitical interests, with similar infrastructure being used in operations referencing Korean policies and diplomatic entities. This suggests that the threat actor, potentially linked to the China-associated Mustang Panda group, operates on multiple fronts using a consistent toolset while tailoring content to each target audience.

DLL Sideloading: A Vulnerability Exploited

The campaign’s infection strategy hinges on exploiting the operating system’s trust in signed software. As the Microsoft_DNX.exe executes, it dynamically loads the LOTUSLITE DLL, redirecting execution into the attacker’s code via the DnxMain export function. This strategy relies on the executable’s signed status, which discourages security products from flagging it as suspicious.

Security analysts are encouraged to monitor for irregular DLL loading patterns from legitimate Microsoft executables and enforce application control policies that restrict DLL loading to verified paths. Any signed executable loading unverified DLLs from user-writable directories should raise suspicion, and endpoint detection tools focusing on behavioral analysis over file reputation offer the best defense against such attacks.

Cyber Security News Tags:APT, banking sector, Cybersecurity, DLL Sideloading, Espionage, India, LOTUSLITE, Microsoft, Mustang Panda, threat group

Post navigation

Previous Post: .NET 10.0.7 Update Fixes Critical Vulnerability
Next Post: Critical Vulnerability in CrowdStrike LogScale Exposed

Related Posts

New Windows-Based DarkCloud Stealer Attacking Computers to Steal Login Credentials and Financial Data New Windows-Based DarkCloud Stealer Attacking Computers to Steal Login Credentials and Financial Data Cyber Security News
Drone Strikes Disrupt AWS Services in UAE Region Drone Strikes Disrupt AWS Services in UAE Region Cyber Security News
Windows Remote Desktop Vulnerability Let Attackers Execute Malicious Code Over Network Windows Remote Desktop Vulnerability Let Attackers Execute Malicious Code Over Network Cyber Security News
LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS Cyber Security News
GitLab Releases Critical Security Updates to Fix Vulnerabilities GitLab Releases Critical Security Updates to Fix Vulnerabilities Cyber Security News
Protecting Sensitive Data in Enterprise Systems for Privacy Compliance Protecting Sensitive Data in Enterprise Systems for Privacy Compliance Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark