Adversary Intelligence — 2026-06-29

Chinese State-Linked Mustang Panda Compromises Indian Government Networks Using Three Novel Malware Tools and Zoho WorkDrive Command Channel

BLUFBeijing now holds persistent, detection-resistant access to Indian strategic planning on hydropower and Taiwan diplomacy through implants hiding inside routine government cloud traffic.

Acronis Threat Research Unit confirmed active Mustang Panda compromises inside Indian government networks, including machines used by senior administrative staff, across two campaigns targeting the government and hydropower sectors with active beaconing observed June 12–22, 2026 12. Both campaigns delivered SHARDLOADER, a new DLL-based loader, through spear-phishing archives lured with hydropower project and India-Taiwan cooperation agreement themes 1. SHARDLOADER stages two new implants: MINIRECON, a WebSocket-based variant derived from the Toneshell malware family, and ZOHOMURK, which embeds hardcoded Zoho OAuth credentials to operate an attacker-controlled WorkDrive account as a dead drop for command-and-control, data exfiltration, and remote task execution 1. Acronis collaborated with CERT-In on victim notification and attributed both campaigns to Mustang Panda with high confidence based on code overlaps with previously documented tooling including TONESHELL 1.

Analysis
Routing C2 through an attacker-controlled Zoho WorkDrive account renders Mustang Panda's beacon traffic indistinguishable from routine cloud storage activity inside Indian government networks, raising the detection threshold for CERT-In. The simultaneous targeting of hydropower infrastructure and Taiwan-cooperation entities reflects deliberate collection against two distinct strategic portfolios, not opportunistic scanning, with the India-Taiwan lure confirming sustained Chinese intelligence interest in India's posture toward Taipei. A live attempt to destroy analyst tools on an identified sandbox indicates both campaigns were under active operator monitoring at discovery. The three-tool kit, sourced to a single Acronis report without independent corroboration, may represent reuse of tested capability against undisclosed prior targets rather than tooling purpose-built for this collection requirement.
2 sources
  1. Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON - Acronis Threat Research Unit
  2. Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE