Skip to content
Chinese APT Targets Indian Banks, Korean Policy Circles

Chinese APT Targets Indian Banks, Korean Policy Circles

Darkreading Nate Nelson April 21, 2026

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific

China is spying on India's financial sector, for some reason, and it's not putting much effort into it, judging by some stale TTPs.

If you knew only two things China's state- advanced persistent threat (APT) Mustang Panda (aka TA416, Bronze President, Stately Taurus), they would probably be, first, that it frequently shifts its tactics, techniques, and procedures (TTPs) , and second, that its focus is solely on geopolitical espionage .

But Mustang Panda seems to have diverged from that target and has trained its sights on India's banking sector.

Square that with its most newly discovered campaign, which employs no interesting TTPs, and though partly focused against American and Korean public policy circles, is aimed largely at financial organizations in India. Despite the differences, researchers at Acronis believe this string of activity belongs to Mustang Panda, thanks to shared code, operational patterns, and more.

The spear-phishing Mustang Panda has been performing ranges from halfway convincing to totally uninspired. Messages sent to targets in India seem to be disguised as basic IT help desk issues, though the researchers lacked any window into whatever email or text messages victims might have received.

While investigating the attacks in India, the researchers also found that the threat actor was also running a Google account impersonating the American political scientist Victor Cha. Cha, formerly the director for Asian affairs for the National Security Council (NSC) during the George W. Bush administration, remains a highly influential figure on North Korea and South Korea, and Indo-Pacific security more generally. The threat actors used a headshot of Cha, and a generically faked email address — [email protected] — to target individuals involved in the US-Korea diplomatic community and policy circles.

This latest variant of LotusLite featured some minor edits to slightly more easily evade cybersecurity detection tools, nothing more. It was also superficially disguised to mimic legitimate banking software in the region where many of its targets were based. In a pop-up window message and an internal code function, the program used the name "HDFC Bank," referring to the largest private bank in the largest country in the world. It appears that the Korean and American targets of this campaign also received the ostensibly India-oriented malware.

Mustang Panda's tradecraft may be stale, but it's not unique in that respect. "A significant portion of nation-state activity relies on simple, well-understood techniques executed with discipline," says Santiago Pontiroli, team lead for the Acronis Threat Research Unit (TRU). "Organizations that focus only on advanced or novel threats risk leaving themselves exposed to exactly this kind of campaign."

The group's evident laziness is understandable, he argues. "Even in environments with formal security programs, these techniques persist because basic controls are often inconsistently implemented. Most organizations, regardless of geography, still struggle with the fundamentals: maintaining visibility into endpoint activity, monitoring for unsigned or improperly loaded DLLs, and detecting abuse of legitimate signed binaries."

Investing less in remarkable new tools and techniques doesn't just save on time and effort in the short term, it also allows threat actors more flexibility in the long term. "It lowers development overhead and keeps tooling disposable. When a campaign is exposed, they can rotate minor indicators, swap the lure, and redeploy quickly. They are not investing in sophistication because they do not need to," Pontrioli explains.

Though the Korean policy-related targeting is more neatly up its alley, Mustang Panda's attacks against India's financial sector are also almost certainly motivated by intelligence gathering, not financial gain.

Pontrioli notes, "We did not observe LotusLite capabilities typically associated with banking malware, such as credential harvesting or payment interception. So the question is not 'Why target a bank for theft?' but 'Why target it for intelligence?'"

To that question, he answers, "India's banking sector, particularly institutions like HDFC Bank, sits at the intersection of several strategic intelligence interests. Financial institutions have visibility into cross-border transactions, government-linked accounts, infrastructure financing, and trade flows, all of which are valuable to a state-aligned actor. Access to this type of data can provide insight into capital movement, economic relationships, and internal policy direction."

He adds, "It may also support broader reconnaissance objectives, such as mapping critical infrastructure or expanding collection beyond traditional government and diplomatic targets."

Nate Nelson is a journalist and scriptwriter. He writes for "Darknet Diaries" — the most popular podcast in cybersecurity — and co-created the former Top 20 tech podcast "Malicious Life." Before joining Dark Reading, he was a reporter at Threatpost.

CISO Survey 2026: The State of Incident Response Readiness

AI SOC for MDR: The Structural Evolution of Managed Detection and Response

How Enterprises Are Developing Secure Applications

KuppingerCole Business Application Risk Management Leadership Compass

2026 CISO AI Risk Report

Defending Against AI-Powered Attacks: The Evolution of Adversarial Machine Learning

Tips for Managing Cloud Security in a Hybrid Environment?

Zero Trust Architecture for Cloud environments: Implementation Roadmap

Security in the AI Age

Identity Maturity Under Pressure: 2026 Findings and How to Catch Up

Extracted Entities

Attack Types (2)

Companies (1)

Industries (1)

Malware (1)

MITRE ATT&CK (1)