Mustang Panda used Zoho WorkDrive as a command channel in attacks against Indian government bodies

Colleagues, a cybersecurity alert: Mustang Panda used Zoho WorkDrive as a command channel in attacks targeting Indian government agencies and hydro‑power infrastructure.
Acronis identified two campaigns and notified CERT‑In: they deployed the SHARDLOADER downloader and MINIRECON and ZOHOMURK implants. ZOHOMURK reads commands from a WorkDrive folder and exfiltrates data.
Delivery via sideloading of signed binaries and ZIP archives; activity observed 12–22 June.
Why it matters: traffic is disguised as normal cloud usage — monitor cloud API calls from unexpected processes (RunOnece, SolidPDFPcl2Bmp task, domain couldinstallup[.]com).
What are your practices for monitoring cloud accounts?
#cybersecurity #APT #cloudsecurity #Zoho

