[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faKV_TtyTQSwaYm60FzupmPeoGSgDDL2wuQjupdwetoc":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"2beb0eb7-18dd-4460-b749-308b005ede95","Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks","mustang-panda-uses-zoho-workdrive-as-command-channel-in-indian-government-attack-5b93a9","The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with","The China-aligned threat actor Mustang Panda is conducting two espionage campaigns against Indian government and hydropower entities. The group is employing new malware, including SHARDLOADER, MINIRECON, and ZOHOMURK, which leverages Zoho WorkDrive as a command and control channel to exfiltrate data and receive instructions, making the malicious activity blend in with legitimate cloud traffic. Acronis Threat Research Unit identified these compromises and is working with CERT-In for remediation.","Mustang Panda targets Indian government with new malware using Zoho WorkDrive for C2.","Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks Ravie LakshmananJun 29, 2026Threat Intelligence \u002F Malware The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with CERT-In on notification and cleanup. The malware abuses Zoho WorkDrive, a cloud storage platform common in India's government sector, to pass commands and exfiltrate data. That is the whole idea: the traffic looks like ordinary cloud activity, so it hides inside the network it is stealing from. Acronis names three new tools. SHARDLOADER is a loader that runs by sideloading a malicious DLL through a legitimately signed binary, a Solid PDF Creator executable in one campaign, and a Citrix Receiver binary in the other. It deploys one of two implants. MINIRECON is a reworked variant of the Toneshell backdoor documented by IBM X-Force, now beaconing over a WebSocket connection on HTTPS. ZOHOMURK is the novel piece: it carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a dead drop, reading commands from an inbox folder and writing stolen output to an outbox. Both campaigns arrive as ZIP archives with the malicious DLL marked hidden. Acronis believes they were delivered by spear-phishing. The lures fit the targets: one themed around a hydropower cooperation proposal, the other around a memorandum of understanding between Indian and Taiwanese institutions. Per Acronis, the goal is intelligence on India's hydropower plans and its defense ties with Taiwan. Acronis attributes the activity to Mustang Panda with high confidence. The report includes the reused Solid PDF Creator sideloading chain, code overlap with Toneshell, command servers sitting in the same network block as infrastructure IBM X-Force tied to the group, and a recurring typo, RunOnece, carried across multiple implants. Operational security was thin. Hardcoded tokens, plaintext identifiers, and reused infrastructure all helped analysts pin it down. Active beaconing ran from June 12 to June 22, 2026. This continues a steady push against Indian targets. In April, Acronis tied the group's LOTUSLITE backdoor to attacks on India's banking sector and South Korean policy circles, also staged through a legitimate cloud service. The broader China-linked interest in India's power sector goes back further: the 2021 RedEcho campaign targeted the country's electricity grid with ShadowPad. There is no patch to apply. The defense is catching the delivery and the cloud abuse. Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser processes. Government and energy organizations, especially those tied to cross-border deals likely to interest Beijing, should watch for geopolitical lures and sideloading from signed binaries. And flag any endpoint process calling cloud APIs that it has no reason to touch. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cloud security, cyber espionage, DLL Sideloading, Malware, Mustang Panda, Spear Phishing, Threat Intelligence, Zoho ⚡ Top Stories This Week Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data ⭐ Featured Resources Get the 2026 Guide to Govern and Secure Enterprise AI Agents at Scale [Watch Demo] See Which Security Gaps Attackers Could Exploit First AI Can’t Stop Every Attack. Learn How Zero Trust Can Block What’s Unknown Have You Outgrown Your MDR? 7 Warning Signs Every CISO Should Check","https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fmustang-panda-uses-zoho-workdrive-as.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEj4479X60pqma2HNkNzrVQuQlGImd-48w4eYTTW-wylTLfK7XfLPtmNOMi79oy48LNiFg-4a_vqF378ZobR2Dy6VTO38VxbsFc_l8xQypwe-V43txSB7f73JS142E4uBXjrLKx0lcS-UOUMZ45kLeYgaqCjg2Je2TElLosoBvARIQpzam5q3ckk5CVXsoAF\u002Fs1600\u002Findia-china.jpg","2026-06-29T15:03:40+00:00","2026-06-29T18:00:20.517942+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"Mustang Panda","threat_actor",{"name":22,"type":23},"Zoho","vendor",{"name":25,"type":26},"Zoho WorkDrive","product",{"name":28,"type":23},"Acronis",{"name":30,"type":26},"Solid PDF Creator",{"name":32,"type":26},"Citrix Receiver","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,44,46,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57,61,64,67,70,74,77,80,83,86,89],{"type":58,"value":59,"context":60},"domain","couldinstallup[.]com","Command and Control domain",{"type":50,"value":62,"context":63},"SHARDLOADER","Loader malware",{"type":50,"value":65,"context":66},"MINIRECON","Reworked Toneshell backdoor variant",{"type":50,"value":68,"context":69},"ZOHOMURK","Novel implant using Zoho WorkDrive for C2",{"type":71,"value":72,"context":73},"mitre_attack","T1059.001","PowerShell (implied by loader\u002Fimplant activity)",{"type":71,"value":75,"context":76},"T1105","Ingress Tool Transfer (via cloud service)",{"type":71,"value":78,"context":79},"T1071.001","Web Protocols (HTTPS\u002FWebSocket for C2)",{"type":71,"value":81,"context":82},"T1573.002","Encrypted Channel (HTTPS)",{"type":71,"value":84,"context":85},"T1027","Obfuscated Files or Information (hidden DLL)",{"type":71,"value":87,"context":88},"T1204.002","Malicious Link\u002FObject (spear-phishing attachment)",{"type":71,"value":90,"context":91},"T1055.012","Process Injection (DLL sideloading)"]