Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft File Exploited in India-Focused Cyber Espionage

Microsoft File Exploited in India-Focused Cyber Espionage

Posted on April 22, 2026 By CWS

A state-backed cyber threat group has been identified executing a covert espionage operation against the Indian banking industry. This operation cleverly utilized a Microsoft-signed file to bypass security measures and deploy malware. The attack introduces a novel variant of the LOTUSLITE backdoor using DLL sideloading, a technique that leverages the inherent trust operating systems place in legitimate executables.

Stealthy Infiltration via Trusted Software

Unlike overt attack methods, the threat actor adopted a stealthy approach, seamlessly integrating malicious actions into normal system operations. The attack is initiated through a ZIP archive themed around the Indian financial sector. Within, a legitimate Microsoft executable, Microsoft_DNX.exe, serves as the unwitting host for the malicious DLL, which is loaded upon execution due to the executable’s lack of comprehensive file path verification.

As part of ongoing monitoring efforts, Acronis Threat Research Unit (TRU) analysts detected this LOTUSLITE variant. The malware’s links to Indian banking institutions became apparent during activity observed in March. TRU researchers highlighted the deliberate use of a Microsoft-signed executable as a means to bypass endpoint security checks, exploiting the general trust extended to Microsoft-signed files.

Persistent Cyber Threats and Espionage Goals

Once the LOTUSLITE backdoor is installed, it connects to a command-and-control (C2) server using dynamic DNS over HTTPS, allowing its traffic to blend with normal encrypted web communications. This backdoor grants the attacker remote shell access, file manipulation capabilities, and session management, ensuring a persistent presence on compromised systems. The backdoor’s design suggests a focus on espionage, prioritizing data gathering and sustained access over causing immediate disruptions.

The campaign shows connections to activities targeting Korea-related geopolitical interests, with similar infrastructure being used in operations referencing Korean policies and diplomatic entities. This suggests that the threat actor, potentially linked to the China-associated Mustang Panda group, operates on multiple fronts using a consistent toolset while tailoring content to each target audience.

DLL Sideloading: A Vulnerability Exploited

The campaign’s infection strategy hinges on exploiting the operating system’s trust in signed software. As the Microsoft_DNX.exe executes, it dynamically loads the LOTUSLITE DLL, redirecting execution into the attacker’s code via the DnxMain export function. This strategy relies on the executable’s signed status, which discourages security products from flagging it as suspicious.

Security analysts are encouraged to monitor for irregular DLL loading patterns from legitimate Microsoft executables and enforce application control policies that restrict DLL loading to verified paths. Any signed executable loading unverified DLLs from user-writable directories should raise suspicion, and endpoint detection tools focusing on behavioral analysis over file reputation offer the best defense against such attacks.

Cyber Security News Tags:APT, banking sector, Cybersecurity, DLL Sideloading, Espionage, India, LOTUSLITE, Microsoft, Mustang Panda, threat group

Post navigation

Previous Post: .NET 10.0.7 Update Fixes Critical Vulnerability
Next Post: Critical Vulnerability in CrowdStrike LogScale Exposed

Related Posts

CrackArmor Flaws Expose Millions of Linux Servers to Risks CrackArmor Flaws Expose Millions of Linux Servers to Risks Cyber Security News
New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads Cyber Security News
OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks Cyber Security News
FBI Alerts on TeamPCP’s Widespread Developer Tool Attacks FBI Alerts on TeamPCP’s Widespread Developer Tool Attacks Cyber Security News
Urgent Alert: Craft CMS Vulnerability Under Attack Urgent Alert: Craft CMS Vulnerability Under Attack Cyber Security News
Here’s How to Spot Them Early Here’s How to Spot Them Early Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark