The Chinese state-sponsored threat actor Mustang Panda has been linked to a series of cyberattacks targeting Indian government entities and energy sectors, using Zoho WorkDrive as a command channel for malware implants.
Background and Context
Mustang Panda is a highly persistent and adaptive cyber espionage group operational since at least 2012. Known by multiple aliases, including Red Delta, TA416, and Stately Taurus, this threat actor has consistently targeted entities of strategic relevance to the People's Republic of China (PRC), using a sophisticated blend of spear-phishing, custom malware, and stealthy command-and-control (C2) operations.
The group's focus is not on headline-grabbing zero-day vulnerabilities but on adequate tradecraft: finely tuned phishing lures, malicious payload obfuscation, and geopolitical targeting. Mustang Panda's targets typically include government agencies, non-governmental organizations (NGOs), think tanks, religious institutions, and civil society organizations across Asia, Europe, Africa, and North America.
The group has been repeatedly linked to China and operations aligned with China's strategic interests. Based on targeting patterns, lure themes, operational characteristics, and code overlaps, the Acronis Threat Research Unit assesses with high confidence that the activity is espionage-motivated and aligned with intelligence collection related to India's hydropower initiatives and defense cooperation with Taiwan.
Attack Chain
The two identified campaigns target India's hydropower sector and government entities engaged in cooperation agreements (MOUs) with Taiwanese government institutions, leveraging a newly discovered malware toolkit comprising SHARDLOADER, MINIRECON, and ZOHOMURK. The SHARDLOADER variants demonstrate moderate sophistication, leveraging persistence and DLL sideloading to deploy two newly identified implants: ZOHOMURK and MINIRECON.
ZOHOMURK is a newly identified implant that leverages Zoho WorkDrive for command-and-control, data exfiltration, and remote task execution. The campaigns showcase new additions to Mustang Panda's malware arsenal while incorporating code overlaps with previously documented tooling, including TONESHELL.
Why it Matters to the Industry
The use of Zoho WorkDrive as a command channel for malware implants highlights the importance of secure cloud storage solutions and the need for robust access controls. The fact that Mustang Panda has been linked to China and operations aligned with China's strategic interests underscores the geopolitical nature of cyber espionage.
For adult-industry platforms and operators, this development serves as a reminder of the ongoing threat landscape and the importance of staying vigilant against sophisticated attacks. The use of multi-stage malware and DLL sideloading techniques emphasizes the need for robust security measures, including regular software updates, secure access controls, and advanced threat detection.
What Comes Next
The Acronis Threat Research Unit has identified multiple compromised systems within India's government sector and collaborated with CERT-In to support mitigation and victim notification efforts. The investigation highlights the importance of collaboration between security researchers, governments, and industry stakeholders in combating cyber threats.
Key Facts
- Mustang Panda is a Chinese state-sponsored threat actor operational since at least 2012.
- The group has consistently targeted entities of strategic relevance to the People's Republic of China (PRC).
- Zoho WorkDrive was used as a command channel for malware implants in the recent attacks.
- SHARDLOADER variants demonstrate moderate sophistication, leveraging persistence and DLL sideloading.
- ZOHOMURK is a newly identified implant that leverages Zoho WorkDrive for command-and-control, data exfiltration, and remote task execution.
- The campaigns showcase new additions to Mustang Panda's malware arsenal while incorporating code overlaps with previously documented tooling.