Adversary Intelligence Operations — 2026-07-10

Chinese APT Mustang Panda Deploys New ZOHOMURK and MINIRECON Malware Against Indian Government and Hydropower Infrastructure

BLUFBy routing command traffic through OAuth-authenticated Zoho accounts, Mustang Panda has rendered India's domain-blocking defenses structurally blind to these intrusions.

GBHackers reported that Acronis Threat Research Unit identified two espionage campaigns by Mustang Panda targeting Indian government offices and hydropower-sector organizations, including entities cooperating with Taiwanese institutions, using spear-phishing archives with geopolitically themed lures 12. Both campaigns used a new loader, SHARDLOADER, to sideload malicious DLLs through signed applications, a Solid PDF Creator executable in the hydropower campaign and a Citrix Receiver binary in the Taiwan-MOU campaign, deploying MINIRECON, a Toneshell-derived implant using WebSocket-over-HTTPS command and control 12. A second malware family, ZOHOMURK, authenticates to attacker-controlled Zoho WorkDrive accounts using embedded OAuth credentials to receive tasking and exfiltrate data through the legitimate cloud platform 12. Acronis attributed the intrusions to Mustang Panda with high confidence, reflecting shared tradecraft, code overlaps with prior Toneshell implants, and C2 infrastructure sharing a network block previously linked to the group by IBM X-Force, with active beaconing observed June 12-22, 2026, and coordinated with India's CERT-In to notify affected parties and share indicators, including the command-and-control domain couldinstallup[.]com 12.

Analysis
Mustang Panda's pivot to Zoho WorkDrive as a command channel defeats domain-blocklist defenses, since OAuth-authenticated traffic to a mainstream cloud platform is indistinguishable from routine business use without application-layer inspection. Parallel tracks against hydropower operators and Taiwan-cooperation government offices indicate deliberate targeting of distinct strategic portfolios rather than opportunistic scanning, and code continuity linking MINIRECON and SHARDLOADER to prior Toneshell implants points to a shared development pipeline within the group's toolset. Reporting remains single-sourced to Acronis TRU, with other outlets merely repeating its findings, though Acronis has now released specific indicators, including the couldinstallup[.]com domain, and coordinated with CERT-In to notify victims, shifting the campaign from detection into remediation. A separate operator reusing shared Toneshell code cannot be ruled out, since the high confidence attribution rests on tradecraft and code overlap rather than infrastructure or signals evidence, leaving most targeted organizations without the OAuth-abuse detection capability needed to catch this activity.
3 sources
  1. Mustang Panda Targets India's Government and Energy Sectors With ZOHOMURK and MINIRECON - GBHackers
  2. Mustang Panda Uses ZOHOMURK and MINIRECON Malware to Threaten India Critical Infrastructure - SharkStriker
  3. Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON - Acronis Threat Research Unit (TRU)

View in full brief →

UNCLASSIFIED // OPEN SOURCE