Acronis Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors
Article Content
- •Mustang Panda targeted India's hydropower and government sectors with new malware.
- •The campaigns used lure documents related to Taiwan, showcasing geopolitical motivations.
- •SHARDLOADER, MINIRECON, and ZOHOMURK were the primary tools used in these attacks.
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering malware including SHARDLOADER, MINIRECON, and ZOHOMURK. These campaigns employed DLL-based loaders and weaponized archives to sideload malicious components. The threat actor demonstrated knowledge of India's software compliance landscape, indicating a sophisticated approach. Both campaigns shared similar tools and techniques, suggesting a moderate retooling effort while maintaining a focus on Indian targets. Acronis has attributed these activities to Mustang Panda, a group linked to China, based on deployment patterns and operational characteristics. The ongoing threat highlights the persistent interest of state-aligned actors in India's critical infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Mustang Panda, Minirecon and CVE-2017-0199 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Mustang Panda Escalates Cyberattacks on European Maritime Sector Chinese hacking group Mustang Panda has intensified cyberespionage campaigns targeting maritime organizations across at least seven EU member states throughout 2025. The European Union Agency for Cybersecurity (ENISA) reported that these attacks primarily focus on espionage and strategic intelligence collection, with…