Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

CISA and Partners Publish Zero Trust Guidance For OT Security

April 30, 2026

Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

April 30, 2026

Europol Busts Albanian Scam Call Centers in Major Online Fraud Case

April 30, 2026
Facebook X (Twitter) Instagram
Thursday, April 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
News

Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

Team-CWDBy Team-CWDApril 30, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that’s distributed via a theme related to India’s banking sector.

“The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations, and session management, indicating a continued espionage-focused capability set rather than financially motivated objectives,” Acronis researchers Subhajeet Singha and Santiago Pontiroli said in an analysis.

The use of LOTUSLITE was previously observed in spear-phishing attacks targeting U.S. government and policy entities using decoys associated with the geopolitical developments between the U.S. and Venezuela. The activity was attributed with medium confidence to a Chinese nation-state group tracked as Mustang Panda.

The latest activity flagged by Acronis involves deploying an evolved version of LOTUSLITE that demonstrates “incremental improvements” over its predecessor, indicating that the malware is being actively maintained and refined by its operators.

The deviation from the prior attack wave relates to a geographic pivot that focuses mainly on the banking sector of India, while keeping the rest of the operational playbook mostly intact. The starting point of the attack is a Compiled HTML (CHM) file embedding the malicious payloads – a legitimate executable and a rogue DLL – along with an HTML page that contains a pop-up which prompts the user to click “Yes.”

This step is designed to silently retrieve and execute a JavaScript malware from a remote server (“cosmosmusic[.]com”), whose primary responsibility is to extract and run the malware contained inside the CHM file using DLL side-loading. The DLL (“dnx.onecore.dll”) is an updated version of LOTUSLITE that communicates with the domain “editor.gleeze[.]com” to receive commands and exfiltrate data of interest.

Further analysis of the campaign has uncovered similar artifacts designed to target South Korean entities, specifically individuals within the policy and diplomatic community.

“We believe that the group had been targeting certain entities belonging to the South Korean and U.S. diplomatic and policy communities, specifically those involved in Korean peninsula affairs, North Korea policy discussions and Indo-Pacific security dialogues,” Acronis said.

“What stands out is the broadening of the group’s targeting, from U.S. government entities with geopolitical lures, to India’s banking sector through implants embedded with HDFC Bank references and pop-ups masquerading as legitimate banking software, and now to South Korean and U.S. policy circles through the impersonation of a prominent figure in Korean peninsula diplomacy, delivered via spoofed Gmail accounts and Google Drive staging.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleEuropol Busts Albanian Scam Call Centers in Major Online Fraud Case
Next Article CISA and Partners Publish Zero Trust Guidance For OT Security
Team-CWD
  • Website

Related Posts

News

CISA and Partners Publish Zero Trust Guidance For OT Security

April 30, 2026
News

Europol Busts Albanian Scam Call Centers in Major Online Fraud Case

April 30, 2026
News

Critical Flaw Turns Vect Ransomware into Data Destroying Wiper

April 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views

Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities

November 27, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Our Picks

In memoriam: David Harley

November 12, 2025

A quick guide to recovering a hacked account

March 21, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.