{"id":234630,"date":"2026-04-22T03:58:00","date_gmt":"2026-04-22T07:58:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/22\/mustang-pandas-new-lotuslite-variant-targets-india-banks-south-korea-policy-circles\/"},"modified":"2026-04-23T06:30:12","modified_gmt":"2026-04-23T10:30:12","slug":"mustang-pandas-new-lotuslite-variant-targets-india-banks-south-korea-policy-circles","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/22\/mustang-pandas-new-lotuslite-variant-targets-india-banks-south-korea-policy-circles\/","title":{"rendered":"Mustang Panda\u2019s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/mustang-pandas-new-lotuslite-variant.html\">Mustang Panda\u2019s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/mustang-pandas-new-lotuslite-variant.html\">https:\/\/thehackernews.com\/2026\/04\/mustang-pandas-new-lotuslite-variant.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-22 03:58:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Apr 22, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Malware<\/span><\/p>\n<p>Cybersecurity researchers have discovered a new variant of a known malware called <strong>LOTUSLITE<\/strong> that&#8217;s distributed via a theme related to India&#8217;s banking sector.<\/p>\n<p>&#8220;The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations, and session management, indicating a continued espionage-focused capability set rather than financially motivated objectives,&#8221; Acronis researchers Subhajeet Singha and Santiago Pontiroli said in an analysis.<\/p>\n<p>The use of LOTUSLITE was previously observed in spear-phishing attacks targeting U.S. government and policy entities using decoys associated with the geopolitical developments between the U.S. and Venezuela. The activity was attributed with medium confidence to a Chinese nation-state group tracked as Mustang Panda.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"548\" data-original-width=\"975\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjeSnuZMsTn46viNI6XBVImY0eE_omV9JpDiEMw4MyRp4OMy7q7NX1C1Nal98_REvwDll7c3zUCB7XaJEiiFPsP5eh0G_T7HABh4PAhuc0R92NED5-MUaTn4lCjLi9o9J21UnWx9JQrU0-MEvooL1P-mdu1EfeFumDu3GopyyS_3YHopnj8c6iqlxisYyLK\/s1600\/chain.jpg\"\/><\/p>\n<p>The latest activity flagged by Acronis involves deploying an evolved version of LOTUSLITE that demonstrates &#8220;incremental improvements&#8221; over its predecessor, indicating that the malware is being actively maintained and refined by its operators.<\/p>\n<p>The deviation from the prior attack wave relates to a geographic pivot that focuses mainly on the banking sector of India, while keeping the rest of the operational playbook mostly intact. The starting point of the attack is a Compiled HTML (CHM) file embedding the malicious payloads \u2013 a legitimate executable and a rogue DLL \u2013 along with an HTML page that contains a pop-up which prompts the user to click &#8220;Yes.&#8221;<\/p>\n<p>This step is designed to silently retrieve and execute a JavaScript malware from a remote server (&#8220;cosmosmusic[.]com&#8221;), whose primary responsibility is to extract and run the malware contained inside the CHM file using DLL side-loading. The DLL (&#8220;dnx.onecore.dll&#8221;) is an updated version of LOTUSLITE that communicates with the domain &#8220;editor.gleeze[.]com&#8221; to receive commands and exfiltrate data of interest.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"718\" data-original-width=\"1000\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiGQcAv2nc7ZwtvHU_Io-3unyJEpC-eeMDcgI1hWeIfoaQmOCPOYdLNWLG73LxehOJWBHseUd3WC_wEEpSpbuEcCT8vwcOK9pJBB1iirRJd_qQi3RWuBr1EdVfkZCtqbr_mGN-rQq3u8trKBGcCzTSRvOHTjUGUfcII-pbBW_hORi5sq_hqUPlRvhbcnDz-\/s1600\/ssl.jpg\"\/><\/p>\n<p>Further analysis of the campaign&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/mustang-pandas-new-lotuslite-variant.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mustang Panda\u2019s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles https:\/\/thehackernews.com\/2026\/04\/mustang-pandas-new-lotuslite-variant.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":234631,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQHPkb7rlS_ueovJaV3s5KxgSQFfHhuZhvW8R8L9wG8j-trZvnmusj4EGvkOPah_XSqgJDLIiRWozv7RtA3o_1VaHYWnaH77PH2kOg2FYkc60uIc6WTf6frjbUp3IwhtB038_wojAl7G5OxcC4aSy5kLF48ssz_3xqLCD7bDbg6_i-RdY8tLvjxlj4Xc0o\/s1600\/indian-banks.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32,25],"class_list":["post-234630","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/234630"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=234630"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/234630\/revisions"}],"predecessor-version":[{"id":234632,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/234630\/revisions\/234632"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/234631"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=234630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=234630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=234630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}