Related Threat Clusters
-
Microsoft-Signed Tooling Used in LOTUSLITE Espionage Against India's Banking Sector
A new variant of the LOTUSLITE backdoor has been deployed against India's banking sector using a Microsoft-signed developer tool. Researchers attribute this campaign to the Mustang Panda espionage group, linked to…
2 articles · Updated April 22, 2026 -
Mustang Panda Targets Indian Banking Sector Amid Geopolitical Tensions
Mustang Panda, a Chinese APT group, has shifted its focus to India's banking sector, utilizing the LOTUSLITE backdoor in recent campaigns. This activity, observed in March 2026, diverges from its typical targets, which…
4 articles · Updated April 21, 2026 -
LOTUSLITE Malware Targets US Government Organizations
Acronis researchers have identified a malware campaign named LOTUSLITE that targets US government-related organizations using politically themed emails with ZIP attachments to install a backdoor for ongoing access. This…
1 article · Updated January 22, 2026 -
LinkedIn Messaging Used in Phishing Campaign to Distribute Malware
A phishing campaign is utilizing LinkedIn private messages to deliver Remote Access Trojans (RATs) through a legitimate open-source penetration testing tool. Cybersecurity researchers from ReliaQuest have identified…
9 articles · Updated January 20, 2026 -
Chinese Hackers Target US Officials with Venezuelan Phishing Campaign
A Chinese-linked cyberespionage group, known as 'Mustang Panda', targeted US government and policy officials using Venezuela-themed phishing emails. This campaign occurred shortly after the US operation to topple former…
11 articles · Updated January 15, 2026
Recent Intelligence Reports
- Mustang Panda linked New LOTUSLITE malware now targets Indian banks: Report — News9Live · April 22, 2026
- Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India — Cybersecuritynews · April 22, 2026
- Microsoft — Gbhackers · April 22, 2026
- Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics — Acronis · April 21, 2026
- Chinese APT Targets Indian Banks, Korean Policy Circles — Darkreading · April 21, 2026
- LOTUSLITE backdoor targets US policy bodies with lures — Itbrief.Au · January 22, 2026
- Threat Actors Leverage LinkedIn Messaging To Deliver Sophisticated Malware — Linkedin · January 20, 2026
- Chinese spies used Maduro's capture as a lure to phish US govt agencies — Theregister · January 15, 2026