Skip to content
Mustang Panda Exploits Zoho WorkDrive in Attacks on Indian Government

Mustang Panda Exploits Zoho WorkDrive in Attacks on Indian Government

First seen 30 Jun 2026, 11:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 1, 2026 at 10:46 UTC

Mustang Panda, a China-aligned cyber espionage group, is conducting dual attack campaigns targeting Indian government and energy sectors. They are utilizing Zoho WorkDrive as a command center, employing newly developed malware tools to exfiltrate sensitive data while camouflaging malicious traffic as legitimate cloud activity. The scope of the attacks is significant, affecting critical infrastructure and government operations. The group has been linked to previous cyber espionage activities, indicating a sustained effort to gather intelligence on Indian operations. Current status shows ongoing investigations and heightened security measures in response to these attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2026-06-29
Malware tools identified
Newly developed malware tools used by Mustang Panda were identified, allowing data theft while disguising malicious traffic.
Thehackernews
2026-06-30
Mustang Panda attacks confirmed
Cyber espionage group Mustang Panda is confirmed to be targeting Indian government and energy sectors using Zoho WorkDrive.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track Mustang Panda and Indian Government in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed