Mustang Panda Exploits Zoho WorkDrive in Attacks on Indian Government

Mustang Panda Exploits Zoho WorkDrive in Attacks on Indian Government

First seen 30 Jun 2026, 11:11 UTC ThehackernewsCybersecuritynews 82% similarity 74.9
Share:

Article Content

Browse articles
ThreatCluster

Mustang Panda, a China-aligned cyber espionage group, is conducting dual attack campaigns targeting Indian government and energy sectors. They are utilizing Zoho WorkDrive as a command center, employing newly developed malware tools to exfiltrate sensitive data while camouflaging malicious traffic as legitimate cloud activity. The scope of the attacks is significant, affecting critical infrastructure and government operations. The group has been linked to previous cyber espionage activities, indicating a sustained effort to gather intelligence on Indian operations. Current status shows ongoing investigations and heightened security measures in response to these attacks.

Key Points: • Mustang Panda targets Indian government and energy sectors using Zoho WorkDrive. • Newly developed malware tools are employed to blend malicious traffic with normal cloud activity. • The attacks represent a significant threat to critical infrastructure and national security.

ThreatCluster AI

Timeline

2026-06-29
Malware tools identified
Newly developed malware tools used by Mustang Panda were identified, allowing data theft while disguising malicious traffic.
Thehackernews
2026-06-30
Mustang Panda attacks confirmed
Cyber espionage group Mustang Panda is confirmed to be targeting Indian government and energy sectors using Zoho WorkDrive.
Cybersecuritynews

Community

Browse all →