The Chinese-linked cyber espionage group Mustang Panda is behind a new campaign in which an updated version of the LOTUSLITE backdoor is used to attack banks in India and individuals connected to South Korean diplomatic and security issues. According to Acronis Threat Research Unit The attacks show that the group continues to develop its tools while broadening its geographic focus and intelligence targets.
The new malware variant is delivered via DLL sideloading, where attackers use legitimate Microsoft-signed files to load malicious code without arousing suspicion. LOTUS LITE then communicates with a command-and-control server via encrypted HTTPS traffic, giving attackers remote control, file management, and session control. According to the researchers, this clearly points to cyberespionage rather than financially motivated attacks.
New attack chain with improved stealth delivery
The attack begins with spear phishing where the victim receives a malicious CHM file with a theme related to the Indian banking sector. When the file is opened, a JavaScript-based loading step is triggered that retrieves and executes malware via DLL sideloading using a legitimate Microsoft component. This allows malicious code to run under the guise of a trusted program, making detection difficult in traditional security solutions.
Acronis notes that the LOTUSLITE variant contains several technical changes compared to previous versions, including new command flags, changed internal identifiers, updated API chains, and new sideloading binaries. At the same time, there are clear traces of previous LOTUSLITE versions, which the researchers say strengthens the connection to Mustang Panda.

From geopolitical lures to financial goals
Mustang Panda has previously primarily targeted government agencies, diplomatic goals and policy-related organizations. What is new in this campaign is that the group is now also targeting the Indian banking sector, while traces of attacks also point to individuals within South Korea's diplomatic and security circles. This suggests a broadening of the group's intelligence focus rather than a mere geographical expansion.
The researchers describe the attacks as an example of how state-linked threat actors continue to use relatively simple but well-proven techniques, where success is based more on social manipulation, relevant decoys, and trusted system components than on advanced exploits.

A growing threat to critical sectors
For security managers, the campaign demonstrates that DLL sideloading, dynamic DNS infrastructure, and legitimate signed binaries remain effective methods for establishing covert access in target environments. At the same time, it shows LOTUSLITE to Mustang Panda actively further develops its tools between campaigns to reduce detection risk and adapt to new targets.
Acronis assesses with moderate confidence that the attacks can be linked to Mustang Panda, based on code similarities, infrastructure patterns, delivery methods, and operational errors that recur from previous campaigns. For banks, governments, and policy organizations, this is yet another reminder that even relatively simple attack chains can pose a serious cyberespionage threat when combined with social engineering and trusted system components.








