Chinese State-Linked Mustang Panda Compromises Indian Government Networks Using Three Novel Malware Tools and Zoho WorkDrive Command Channel
Acronis Threat Research Unit confirmed active
Routing C2 through an attacker-controlled Zoho WorkDrive account renders Mustang Panda's beacon traffic indistinguishable from routine cloud storage activity inside Indian government networks, raising the detection threshold for CERT-In. The simultaneous targeting of hydropower infrastructure and Taiwan-cooperation entities reflects deliberate collection against two distinct strategic portfolios, not opportunistic scanning, with the India-Taiwan lure confirming sustained Chinese intelligence interest in India's posture toward Taipei. A live attempt to destroy analyst tools on an identified sandbox indicates both campaigns were under active operator monitoring at discovery. The three-tool kit, sourced to a single Acronis report without independent corroboration, may represent reuse of tested capability against undisclosed prior targets rather than tooling purpose-built for this collection requirement.
2 sources
- Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON -
Acronis Threat Research Unit - Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks -
The Hacker News