LOTUSLITE is a custom Windows backdoor used in targeted cyber-espionage campaigns and repeatedly linked with moderate confidence to the China-aligned threat actor Mustang Panda. Reported campaigns targeted U.S. government and policy-focused organizations using Venezuela-themed spear-phishing lures, India’s banking sector, and South Korean and U.S. diplomatic/policy communities. Delivery commonly relies on DLL sideloading with legitimate signed executables, including Tencent KuGou components and Microsoft-signed binaries such as Microsoft_DNX.exe; one reported chain also used a malicious CHM file containing a legitimate executable, rogue DLL, and HTML lure. Observed malicious DLL names include kugou.dll, dnx.onecore.dll, libmemobook.dll, and an AMPV.dll-impersonating DLL.
Across reporting, LOTUSLITE provides espionage-oriented remote access capabilities rather than banking fraud functionality. Documented functions include remote shell access via cmd.exe, remote command execution, file and directory enumeration, file manipulation and arbitrary file writing, session management/control, host profiling, beaconing, and data exfiltration. Multiple reports state it communicates with command-and-control over HTTPS or TCP/443 while masquerading as benign web traffic using spoofed headers such as forms.microsoft.com or Google-themed traffic. Reported infrastructure includes hardcoded or observed C2 endpoints 172.81.60.97, 103.79.77.181, editor.gleeze.com, and www.cosmosmusic.com.
Persistence mechanisms vary by campaign and version but include HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries such as Lite360, ACboardCm, ASEdge, and DadaBank, along with dropped files and directories under C:\ProgramData\Technology360NB, C:\ProgramData\Microsoft_DNX, C:\ProgramData\CClipboardCm, C:\ProgramData\WebFeatures, and C:\ProgramData\SmartPrint. Additional reported artifacts include mutexes Global\Technology360-A@P@T-Team and BelievemeIamMustang-Panda, launcher names such as DataTechnology.exe and SafeChrome.exe, and command protocol magic values including 0x8899AABB and 0xB2EBCFDF. Reported sample hashes include 47e51e82229e80a387c3cb100d39d3705e6360bbf9bfa1601dbc484e8d02e653 and 15b0f927bb43c6e3b9b002cbeac2faf6975e52503c32f039c8c4ecf6be600fdd, with additional campaign-linked hashes af31ebe9085df408bedcf8f027fb60389897e5c8d3b0e9695fea29774f9d3aec, cc0ff7e25ea686171919575916e2d9ebaeb5800a063f370a6980ea791f8851b8, 7beede15ecdc7d3f01db4b699e5fe5f4f2e7c79cd7ef0e918ed0583bf621de7d, 9bf2f3b15a621789f898f9bd7710ba857e3f238a4937b64fdc47ef9a92e0b05d, 18bc0e0f627d90fb283aa243055b46d0bfb5d85a7240d8f63ec2d1c8a2c15893, and 6d22d50634c2c2fc853bfd2b564e1837d51087aa684a9c4415634c8c13c44135.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The binary shares numerous similarities with the analysis published on May 13, 2026, titled “MustangPanda New Backdoor LotusLite”.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The use of LOTUSLITE was previously observed in spear-phishing attacks targeting U.S. government and policy entities using decoys associated with the geopolitical developments between the U.S. and Venezuela.
This file appears to be packaged in a zip archive along with its legitimate, signed loader, and sent by email using appealing headlines. In this case, the zip filenames is “Conference_invitation” and the legitimate executable is named “Ph-china_Joint_Ministerial_Meeting.Scr”.
The malware communicates with a dynamic DNS-based C2 over HTTPS and enables remote shell access, file operations, and session control, indicating espionage-driven objectives.
external.ExecuteShellCommand() calls powershell.exe with: -ExecutionPolicy Bypass -WindowStyle Hidden Downloads svchost.exe, executes from %TEMP% hidden.
The supported commands are as follows: ID Command 1 Write to cmd.exe stdin ... 10 Create a hidden cmd.exe and redirect its I/O 11 Kill the cmd.exe
All WinINet, kernel32, shell, and process APIs are resolved at runtime via a PEB walk mechanism.
Interestingly, the DLL appears to be impersonating “AMPV.dll”, a DLL seemingly used in “Samsung Series” software, which would be consistent with this masquerading attempt.
Numerous strings are decrypted on the fly, making generic identification of the implant significantly more difficult.
"On the first run, the downloader performs checks to determine whether LOTUSLITE is already installed. It looks for two files under C:\ProgramData\CClipboardCm\... verifies that both files match expected file sizes."
If both conditions are met, it fingerprints the machine and prepares a buffer as follows: [USERNAME]|[COMPUTERNAME]
The supported commands are as follows: ... 3 Directory listing ... 13 Change current directory
The malware establishes a connection to 103.79.77[.]181 ... POST https://forms.microsoft.com/info/faq/v6 ... Host: forms.microsoft.com
The HTTP connection is initialized while spoofing a Microsoft domain: POST https://forms.microsoft.com/info/faq/v6 ... Host: forms.microsoft.com
The supported commands are as follows: ... 14 Write an arbitrary file
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware tool previously linked by Acronis to Mustang Panda in earlier campaigns targeting India’s banking sector and South Korean policy circles.
Backdoor previously linked by Acronis to Mustang Panda attacks on India's banking sector and South Korean policy targets.
A Windows backdoor/implant delivered via a dropper masquerading as a PDF-related file, establishing persistence via HKCU Run, fingerprinting the host, and communicating with C2 over spoofed HTTPS requests to forms.microsoft.com while disabling TLS validation. It supports remote shell interaction, directory listing, session termination, changing directories, and arbitrary file write.
LOTUSLITE is a backdoor used for espionage-oriented intrusions. In this report, it uses DLL sideloading with legitimate Microsoft-signed executables, communicates with a dynamic DNS-based C2 over HTTPS, and supports remote shell access, file operations, and session control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.