Chinese APT Mustang Panda Deploys New ZOHOMURK and MINIRECON Malware Against Indian Government and Hydropower Infrastructure
GBHackers reported that Acronis Threat Research Unit identified two espionage campaigns by Mustang Panda targeting Indian government offices and hydropower-sector organizations, including entities cooperating with Taiwanese institutions, using spear-phishing archives with geopolitically themed lures
Mustang Panda's pivot to Zoho WorkDrive as a command channel defeats domain-blocklist defenses, since OAuth-authenticated traffic to a mainstream cloud platform is indistinguishable from routine business use without application-layer inspection. Parallel tracks against hydropower operators and Taiwan-cooperation government offices indicate deliberate targeting of distinct strategic portfolios rather than opportunistic scanning, and code continuity linking MINIRECON and SHARDLOADER to prior Toneshell implants points to a shared development pipeline within the group's toolset. Reporting remains single-sourced to Acronis TRU, with other outlets merely repeating its findings, though Acronis has now released specific indicators, including the couldinstallup[.]com domain, and coordinated with CERT-In to notify victims, shifting the campaign from detection into remediation. A separate operator reusing shared Toneshell code cannot be ruled out, since the high confidence attribution rests on tradecraft and code overlap rather than infrastructure or signals evidence, leaving most targeted organizations without the OAuth-abuse detection capability needed to catch this activity.
3 sources
- Mustang Panda Targets India's Government and Energy Sectors With ZOHOMURK and MINIRECON -
GBHackers - Mustang Panda Uses ZOHOMURK and MINIRECON Malware to Threaten India Critical Infrastructure -
SharkStriker - Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON -
Acronis Threat Research Unit (TRU)