Chinese-Linked Mustang Panda Deploys LotusLite Backdoor Against Indian Financial Institutions
Mustang Panda is an advanced persistent threat group believed to have links to China and has previously focused primarily on government and diplomatic targets. Its shift toward Indian financial institutions indicates that its intelligence-gathering activities have expanded into the financial system. The targeting of a South Korean foreign-policy organization also highlights the cross-industry risks posed by regional cyberespionage campaigns.
Cybersecurity company Acronis recently disclosed that Mustang Panda was distributing the new LotusLite backdoor through malicious CHM help files. The campaign targeted at least two groups: India's financial sector and South Korea's foreign-policy community. The report did not disclose the exact dates of the attacks, the number of affected organizations or the amount of losses, and no further data was available as of July 20, 2026.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.