Mark RadarMARK RADAR
EN

Chinese-Linked Mustang Panda Deploys LotusLite Backdoor Against Indian Financial Institutions

1 reports · First detected 2026-04-23 · Last active 2026-04-23

Mustang Panda is an advanced persistent threat group believed to have links to China and has previously focused primarily on government and diplomatic targets. Its shift toward Indian financial institutions indicates that its intelligence-gathering activities have expanded into the financial system. The targeting of a South Korean foreign-policy organization also highlights the cross-industry risks posed by regional cyberespionage campaigns.

Cybersecurity company Acronis recently disclosed that Mustang Panda was distributing the new LotusLite backdoor through malicious CHM help files. The campaign targeted at least two groups: India's financial sector and South Korea's foreign-policy community. The report did not disclose the exact dates of the attacks, the number of affected organizations or the amount of losses, and no further data was available as of July 20, 2026.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)