{"id":1507,"date":"2026-06-29T18:12:55","date_gmt":"2026-06-29T18:12:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1507"},"modified":"2026-06-29T18:12:55","modified_gmt":"2026-06-29T18:12:55","slug":"mustang-panda-uses-zoho-workdrive-as-command-channel-in-indian-government-attacks","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1507","title":{"rendered":"Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 29, 2026<\/span><\/span><span class=\"p-tags\">Threat Intelligence \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj4479X60pqma2HNkNzrVQuQlGImd-48w4eYTTW-wylTLfK7XfLPtmNOMi79oy48LNiFg-4a_vqF378ZobR2Dy6VTO38VxbsFc_l8xQypwe-V43txSB7f73JS142E4uBXjrLKx0lcS-UOUMZ45kLeYgaqCjg2Je2TElLosoBvARIQpzam5q3ckk5CVXsoAF\/s1700-e365\/india-china.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The China-aligned espionage group\u00a0<a href=\"https:\/\/attack.mitre.org\/groups\/G0129\/\">Mustang Panda<\/a>\u00a0is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel.<\/p>\n<p><a href=\"https:\/\/www.acronis.com\/en\/tru\/posts\/mustang-panda-targets-indias-government-and-energy-sectors\/\">Acronis Threat Research Unit<\/a>\u00a0found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with\u00a0<a href=\"https:\/\/www.cert-in.org.in\/\">CERT-In<\/a>\u00a0on notification and cleanup.<\/p>\n<p>The malware abuses\u00a0<a href=\"https:\/\/www.zoho.com\/workdrive\/\">Zoho WorkDrive<\/a>, a cloud storage platform common in India&#8217;s government sector, to pass commands and exfiltrate data. That is the whole idea: the traffic looks like ordinary cloud activity, so it hides inside the network it is stealing from.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Acronis names three new tools.<\/p>\n<ul>\n<li><b>SHARDLOADER <\/b>is a loader that runs by sideloading a malicious DLL through a legitimately signed binary, a Solid PDF Creator executable in one campaign, and a Citrix Receiver binary in the other. It deploys one of two implants.<\/li>\n<li><b>MINIRECON <\/b>is a reworked variant of the Toneshell backdoor\u00a0<a href=\"https:\/\/www.ibm.com\/think\/x-force\/hive0154-drops-updated-toneshell-backdoor\">documented by IBM X-Force<\/a>, now beaconing over a WebSocket connection on HTTPS.<\/li>\n<li><b>ZOHOMURK <\/b>is the novel piece: it carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a dead drop, reading commands from an inbox folder and writing stolen output to an outbox.<\/li>\n<\/ul>\n<p>Both campaigns arrive as ZIP archives with the malicious DLL marked hidden. Acronis believes they were delivered by spear-phishing. The lures fit the targets: one themed around a hydropower cooperation proposal, the other around a memorandum of understanding between Indian and Taiwanese institutions.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhQmk98KFrFYERbtI3uXGfmrEPyCrJgHUtublqZJ0UaP7Wilvi1jw5pk3wluzz-2n0wk0fqXsaZULjjKOb4NjyUQ8NhnMQUTMp5rU_dHZue4hNSV3Ue-kCswz6-SiDmF4p8A1oDf09VgzcqL21U25ZDS-i-z67gOjgyV16s6r0soA5TBZgZeM2jSevlkDMG\/s1700-e365\/camp.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhQmk98KFrFYERbtI3uXGfmrEPyCrJgHUtublqZJ0UaP7Wilvi1jw5pk3wluzz-2n0wk0fqXsaZULjjKOb4NjyUQ8NhnMQUTMp5rU_dHZue4hNSV3Ue-kCswz6-SiDmF4p8A1oDf09VgzcqL21U25ZDS-i-z67gOjgyV16s6r0soA5TBZgZeM2jSevlkDMG\/s1700-e365\/camp.png\" alt=\"\" border=\"0\" data-original-height=\"1027\" data-original-width=\"1531\"\/><\/a><\/div>\n<p>Per Acronis, the goal is intelligence on India&#8217;s hydropower plans and its defense ties with Taiwan. Acronis attributes the activity to Mustang Panda with high confidence.<\/p>\n<p>The report includes the reused Solid PDF Creator sideloading chain, code overlap with Toneshell, command servers sitting in the same network block as infrastructure IBM X-Force tied to the group, and a recurring typo,\u00a0RunOnece, carried across multiple implants.<\/p>\n<p>Operational security was thin. Hardcoded tokens, plaintext identifiers, and reused infrastructure all helped analysts pin it down. Active beaconing ran from June 12 to June 22, 2026.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>This continues a steady push against Indian targets. In April, Acronis tied the group&#8217;s\u00a0LOTUSLITE backdoor\u00a0to attacks on India&#8217;s banking sector and South Korean policy circles, also staged through a legitimate cloud service. The broader China-linked interest in India&#8217;s power sector goes back further: the 2021\u00a0<a href=\"https:\/\/www.recordedfuture.com\/research\/redecho-targeting-indian-power-sector\">RedEcho campaign<\/a>\u00a0targeted the country&#8217;s electricity grid\u00a0with ShadowPad.<\/p>\n<p>There is no patch to apply. The defense is catching the delivery and the cloud abuse. Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named\u00a0SolidPDFPcl2Bmp, the C2 domain\u00a0couldinstallup[.]com, and the Zoho user agents that turn up on non-browser processes.<\/p>\n<p>Government and energy organizations, especially those tied to cross-border deals likely to interest Beijing, should watch for geopolitical lures and sideloading from signed binaries. And flag any endpoint process calling cloud APIs that it has no reason to touch.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 29, 2026Threat Intelligence \/ Malware The China-aligned espionage group\u00a0Mustang Panda\u00a0is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1508,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[24,1163,1223,385,2237,1342,2236,276,275],"class_list":["post-1507","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attacks","tag-channel","tag-command","tag-government","tag-indian","tag-mustang","tag-panda","tag-workdrive","tag-zoho"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1507","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1507"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1507\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1508"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1507"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1507"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}