Skip to content
ThreatCluster

Microsoft-Signed Tooling Used in LOTUSLITE Espionage Against India's Banking Sector

First seen 22 Apr 2026, 07:34 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 22, 2026 at 19:54 UTC
  • LOTUSLITE backdoor variant targets India's banking sector using Microsoft-signed binaries.
  • Attack method involves DLL sideloading to exploit trust in signed files.
  • Mustang Panda group, linked to Chinese state interests, is suspected in the operation.

A new variant of the LOTUSLITE backdoor has been deployed against India's banking sector using a Microsoft-signed developer tool. Researchers attribute this campaign to the Mustang Panda espionage group, linked to Chinese state interests. The backdoor provides remote shell access and file operations, focusing on espionage rather than financial gain. The attack employs DLL sideloading to bypass security measures, exploiting the trust placed in Microsoft-signed binaries. This operation highlights vulnerabilities in trusted software that can be leveraged for state-sponsored cyber espionage. The full scope of the impact is still being assessed, but the targeted sector is critical to India's economy. Current mitigation strategies are not detailed in the articles. Ongoing investigations are expected to provide further insights into the attack vector and potential defenses.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 153d ago How this analysis works

Timeline

2026-04-22
Microsoft-signed tooling identified in LOTUSLITE espionage campaign
Recent
Ongoing investigations into the attack and its impact

More articles in this cluster (2)

Following this threat?

Track Mustang Panda and Lotuslite in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed