Skip to content
Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors

Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors

First seen 30 Jun 2026, 08:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 1, 2026 at 08:04 UTC

In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering malware including SHARDLOADER, MINIRECON, and ZOHOMURK. These campaigns employed DLL-based loaders and weaponized archives to sideload malicious components. The threat actor demonstrated knowledge of India's software compliance landscape, indicating a sophisticated approach. Both campaigns shared similar tools and techniques, suggesting a moderate retooling effort while maintaining a focus on Indian targets. Acronis has attributed these activities to Mustang Panda, a group linked to China, based on deployment patterns and operational characteristics. The ongoing threat highlights the persistent interest of state-aligned actors in India's critical infrastructure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-01
Espionage campaigns initiated
Mustang Panda began targeting Indian government and hydropower sectors with tailored lure documents.
Gbhackers
2026-06-29
Acronis report published
Acronis identified the campaigns and detailed the malware used, attributing them to Mustang Panda.
Acronis
2026-06-30
Gbhackers report published
Gbhackers confirmed the ongoing espionage campaigns and provided additional details on the malware suite.
Gbhackers

More articles in this cluster (5)

Following this threat?

Track Mustang Panda, Minirecon and CVE-2017-0199 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed