Microsoft-Signed Tooling Used in LOTUSLITE Espionage Against India's Banking Sector
Article Content
- •LOTUSLITE backdoor variant targets India's banking sector using Microsoft-signed binaries.
- •Attack method involves DLL sideloading to exploit trust in signed files.
- •Mustang Panda group, linked to Chinese state interests, is suspected in the operation.
A new variant of the LOTUSLITE backdoor has been deployed against India's banking sector using a Microsoft-signed developer tool. Researchers attribute this campaign to the Mustang Panda espionage group, linked to Chinese state interests. The backdoor provides remote shell access and file operations, focusing on espionage rather than financial gain. The attack employs DLL sideloading to bypass security measures, exploiting the trust placed in Microsoft-signed binaries. This operation highlights vulnerabilities in trusted software that can be leveraged for state-sponsored cyber espionage. The full scope of the impact is still being assessed, but the targeted sector is critical to India's economy. Current mitigation strategies are not detailed in the articles. Ongoing investigations are expected to provide further insights into the attack vector and potential defenses.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Mustang Panda and Lotuslite in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…