Skip to content
Mustang Panda Targets Indian Banking Sector Amid Geopolitical Tensions

Mustang Panda Targets Indian Banking Sector Amid Geopolitical Tensions

First seen 21 Apr 2026, 22:15 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 22, 2026 at 19:54 UTC
  • Mustang Panda has targeted the Indian banking sector using the LOTUSLITE backdoor.
  • Spear phishing tactics involve malicious CHM files disguised as IT support requests.
  • The campaign also targets American and Korean policy circles, indicating broader geopolitical interests.

Mustang Panda, a Chinese APT group, has shifted its focus to India's banking sector, utilizing the LOTUSLITE backdoor in recent campaigns. This activity, observed in March 2026, diverges from its typical targets, which include government entities, and indicates a potential geopolitical espionage motive. The attack vector primarily involves spear phishing, with malicious CHM files disguised as IT support requests sent to banking institutions. The malware features minor modifications to evade detection and mimics legitimate banking software, specifically referencing HDFC Bank. Researchers from Acronis have linked this campaign to Mustang Panda based on shared code and operational patterns. Additionally, the group has targeted American and Korean policy circles, using impersonation tactics. The overall technical sophistication of the attacks remains low, with stale TTPs noted by analysts. The investigation is ongoing, with further analysis needed to understand the full scope of the threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 141d ago How this analysis works

Timeline

2026-03-01
New LOTUSLITE backdoor activity observed targeting Indian banks
2026-04-21
Acronis publishes report linking attacks to Mustang Panda
2026-04-21
Malicious CHM files identified in spear phishing campaigns

More articles in this cluster (5)

Following this threat?

Track Bronze President, Lotuslite and HDFC Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed