Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mustang Panda Exploits Cloud Service in Indian Cyber Attacks

Mustang Panda Exploits Cloud Service in Indian Cyber Attacks

Posted on June 29, 2026 By CWS

The cyber-espionage group Mustang Panda, known for its ties to China, has launched two distinct cyber campaigns targeting Indian government entities and hydropower sectors. These operations involve the deployment of newly developed malware and the innovative use of a legitimate cloud service as a command-and-control channel.

Targeted Cyber Attacks on Indian Networks

Analysis by the Acronis Threat Research Unit uncovered active infiltrations within Indian governmental networks, including devices used by high-ranking officials. Acronis collaborated with CERT-In to address and mitigate the security breaches. The malware strategically leverages Zoho WorkDrive, a widely-used cloud storage service in Indian government operations, to execute commands and extract sensitive data, effectively masking its activities as standard cloud traffic.

Innovative Malware Toolset

Acronis identified three novel tools used in these campaigns. SHARDLOADER is a loader designed to execute by sideloading a harmful DLL through a signed binary, such as a Solid PDF Creator executable or a Citrix Receiver binary, deploying one of two implants. MINIRECON, a modified version of the Toneshell backdoor, communicates via a WebSocket over HTTPS. Lastly, ZOHOMURK, the latest addition, employs hardcoded Zoho OAuth credentials to exploit a compromised WorkDrive account, facilitating command execution and data exfiltration through designated folders.

The attacks are delivered via ZIP files containing concealed malicious DLLs, believed to be distributed through spear-phishing methods. The bait aligns with the targets: documents themed around hydropower cooperation and a memorandum between Indian and Taiwanese organizations. The primary aim appears to be gathering intelligence on India’s hydropower strategies and its defense collaborations with Taiwan.

Security and Strategic Implications

Acronis attributes these activities to Mustang Panda with high confidence, citing evidence such as reused code and infrastructure connections. The group’s operational security flaws, including hardcoded tokens and reused identifiers, facilitated the identification of these cyber threats. The attacks were actively monitored between June 12 and June 22, 2026.

This series of cyber assaults continues a pattern of targeted attacks on Indian entities. In April, Mustang Panda was linked to the LOTUSLITE backdoor used against India’s banking sector and South Korean policy circles, also exploiting legitimate cloud services. Historical context includes the 2021 RedEcho campaign targeting India’s power grid with ShadowPad malware.

Future Outlook and Recommendations

No immediate software patches are available to counter these threats. Instead, organizations are advised to focus on intercepting the delivery methods and cloud service exploitation. Acronis has shared indicators and detection strategies, including persistence mechanisms, specific scheduled tasks, and unusual Zoho user agent activities.

Entities within government and energy sectors, particularly those involved in international collaborations potentially of interest to Beijing, should remain vigilant. Monitoring for geopolitical-themed phishing lures and unauthorized cloud API interactions is crucial in fortifying defenses against these sophisticated cyber threats.

The Hacker News Tags:Acronis, CERT-In, China-aligned group, cloud service abuse, cyber attacks, Cybersecurity, Espionage, geopolitical tensions, hydropower sector, Indian government, Malware, malware detection, Mustang Panda, Mustang Panda tools, Zoho WorkDrive

Post navigation

Previous Post: WhatsApp Introduces Handles for Enhanced Privacy

Related Posts

GitHub Breach Linked to Malicious VS Code Extension GitHub Breach Linked to Malicious VS Code Extension The Hacker News
Cisco Fixes Critical Flaws in Identity and Webex Services Cisco Fixes Critical Flaws in Identity and Webex Services The Hacker News
Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan The Hacker News
Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments The Hacker News
Russian Group Linked to Malware Attacks on Ukraine Russian Group Linked to Malware Attacks on Ukraine The Hacker News
Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mustang Panda Exploits Cloud Service in Indian Cyber Attacks
  • WhatsApp Introduces Handles for Enhanced Privacy
  • Straiker Secures $64M to Enhance AI Security Solutions
  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Exploit Released for Splunk Secure Gateway Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mustang Panda Exploits Cloud Service in Indian Cyber Attacks
  • WhatsApp Introduces Handles for Enhanced Privacy
  • Straiker Secures $64M to Enhance AI Security Solutions
  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Exploit Released for Splunk Secure Gateway Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark