Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft File Exploited in India-Focused Cyber Espionage

Microsoft File Exploited in India-Focused Cyber Espionage

Posted on April 22, 2026 By CWS

A state-backed cyber threat group has been identified executing a covert espionage operation against the Indian banking industry. This operation cleverly utilized a Microsoft-signed file to bypass security measures and deploy malware. The attack introduces a novel variant of the LOTUSLITE backdoor using DLL sideloading, a technique that leverages the inherent trust operating systems place in legitimate executables.

Stealthy Infiltration via Trusted Software

Unlike overt attack methods, the threat actor adopted a stealthy approach, seamlessly integrating malicious actions into normal system operations. The attack is initiated through a ZIP archive themed around the Indian financial sector. Within, a legitimate Microsoft executable, Microsoft_DNX.exe, serves as the unwitting host for the malicious DLL, which is loaded upon execution due to the executable’s lack of comprehensive file path verification.

As part of ongoing monitoring efforts, Acronis Threat Research Unit (TRU) analysts detected this LOTUSLITE variant. The malware’s links to Indian banking institutions became apparent during activity observed in March. TRU researchers highlighted the deliberate use of a Microsoft-signed executable as a means to bypass endpoint security checks, exploiting the general trust extended to Microsoft-signed files.

Persistent Cyber Threats and Espionage Goals

Once the LOTUSLITE backdoor is installed, it connects to a command-and-control (C2) server using dynamic DNS over HTTPS, allowing its traffic to blend with normal encrypted web communications. This backdoor grants the attacker remote shell access, file manipulation capabilities, and session management, ensuring a persistent presence on compromised systems. The backdoor’s design suggests a focus on espionage, prioritizing data gathering and sustained access over causing immediate disruptions.

The campaign shows connections to activities targeting Korea-related geopolitical interests, with similar infrastructure being used in operations referencing Korean policies and diplomatic entities. This suggests that the threat actor, potentially linked to the China-associated Mustang Panda group, operates on multiple fronts using a consistent toolset while tailoring content to each target audience.

DLL Sideloading: A Vulnerability Exploited

The campaign’s infection strategy hinges on exploiting the operating system’s trust in signed software. As the Microsoft_DNX.exe executes, it dynamically loads the LOTUSLITE DLL, redirecting execution into the attacker’s code via the DnxMain export function. This strategy relies on the executable’s signed status, which discourages security products from flagging it as suspicious.

Security analysts are encouraged to monitor for irregular DLL loading patterns from legitimate Microsoft executables and enforce application control policies that restrict DLL loading to verified paths. Any signed executable loading unverified DLLs from user-writable directories should raise suspicion, and endpoint detection tools focusing on behavioral analysis over file reputation offer the best defense against such attacks.

Cyber Security News Tags:APT, banking sector, Cybersecurity, DLL Sideloading, Espionage, India, LOTUSLITE, Microsoft, Mustang Panda, threat group

Post navigation

Previous Post: .NET 10.0.7 Update Fixes Critical Vulnerability
Next Post: Critical Vulnerability in CrowdStrike LogScale Exposed

Related Posts

Tackling Alert Fatigue: Boost SOC Efficiency with Smart Strategies Tackling Alert Fatigue: Boost SOC Efficiency with Smart Strategies Cyber Security News
Top 10 Best Practices for Securing Your Database Top 10 Best Practices for Securing Your Database Cyber Security News
New Zip Slip Vulnerability Allows Attackers to Manipulate ZIP Files During Decompression New Zip Slip Vulnerability Allows Attackers to Manipulate ZIP Files During Decompression Cyber Security News
Kubernetes Misconfigurations Enable Dangerous Cloud Exploits Kubernetes Misconfigurations Enable Dangerous Cloud Exploits Cyber Security News
CSS Vulnerability Turns Emails into Keyloggers CSS Vulnerability Turns Emails into Keyloggers Cyber Security News
APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark