VMTech
Discuss a project

Mustang Panda used Zoho WorkDrive as a command channel in attacks against Indian government bodies

Mustang Panda used Zoho WorkDrive as a command channel in attacks against Indian government bodies

Colleagues, a cybersecurity alert: Mustang Panda used Zoho WorkDrive as a command channel in attacks targeting Indian government agencies and hydro‑power infrastructure.

Acronis identified two campaigns and notified CERT‑In: they deployed the SHARDLOADER downloader and MINIRECON and ZOHOMURK implants. ZOHOMURK reads commands from a WorkDrive folder and exfiltrates data.

Delivery via sideloading of signed binaries and ZIP archives; activity observed 12–22 June.

Why it matters: traffic is disguised as normal cloud usage — monitor cloud API calls from unexpected processes (RunOnece, SolidPDFPcl2Bmp task, domain couldinstallup[.]com).

What are your practices for monitoring cloud accounts?

#cybersecurity #APT #cloudsecurity #Zoho

Open analytics
On the site 1 views
min read 1 29.06.2026
On Instagram 3 views
On Instagram 2 reach
Instagram

Mustang Panda used Zoho WorkDrive as a command channel in attacks against Indian government bodies

Open the post on Instagram ↗