A China-linked espionage group tracked as Mustang Panda targeted India’s banking sector and South Korean policy circles with an updated LOTUSLITE backdoor, according to Acronis Threat Research. In India, the attackers used HDFC Bank-themed .chm lure files that fetched a JavaScript payload from cosmosmusic[.]com, displayed fake banking pop-ups, and established persistence on infected systems. In South Korea, the operation used a fake Gmail account impersonating Victor Cha and malicious invitation documents hosted on Google Drive to target policy-makers and geopolitical experts.
Researchers said the newer LOTUSLITE v1.1 variant improves stealth through DLL sideloading with legitimate Microsoft-signed executables, runtime API resolution via ntdll.dll call chains, and altered network markers and command flags. Acronis attributed the campaign to Mustang Panda with moderate confidence, citing shared code lineage, reused infrastructure, overlapping command structures, use of Dynu Systems dynamic DNS, and recurring operational patterns linking the India and South Korea intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In the South Korean targeting, the attackers impersonated Victor Cha using the Gmail account victorcha707@gmail.com and sent Google Drive links containing fake invitation letters for policy-makers. The lure used folders named 'March 30' as part of the infection attempt.
Acronis Threat Research Unit said the espionage campaign was first observed in March 2026, targeting India’s banking sector and South Korean policy circles. The activity used an updated LOTUSLITE backdoor and marked an expansion beyond the group’s earlier focus on U.S. government entities.
Acronis Threat Research Unit published research detailing the India and South Korea campaign, including LOTUSLITE v1.1 changes such as DLL sideloading, runtime API resolution, and modified protocol markers. The researchers attributed the activity to Mustang Panda with moderate confidence based on shared code lineage, reused infrastructure, command overlaps, Dynu Systems dynamic DNS usage, and recurring operational patterns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
secureblink.com
Open sourceacronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.