Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
Mustang Panda, a China-aligned espionage group, is using Zoho WorkDrive as a command channel in attacks on the Indian government and hydropower targets. The group is deploying new malware and abusing the legitimate cloud service to pass commands and exfiltrate data.
Intelligence analysis by Llama 3.3 70B

The attacks involve the use of new malware tools, including SHARDLOADER, MINIRECON, and ZOHOMURK, which are designed to evade detection and exploit the trust placed in legitimate cloud services.
Imagine you have a safe box where you store important documents. Now, imagine someone finds a way to open that safe box without you knowing, and they use it to send and receive secret messages. That's kind of what's happening here, but instead of a safe box, it's a cloud storage service that's being used by hackers to steal information.
Analysis
Introduction to Mustang Panda's Tactics
The China-aligned espionage group Mustang Panda has been identified as the perpetrator of a series of attacks on the Indian government and hydropower targets. The group's tactics involve the use of new malware tools, including SHARDLOADER, MINIRECON, and ZOHOMURK, which are designed to evade detection and exploit the trust placed in legitimate cloud services.
The Role of Zoho WorkDrive in the Attacks
Zoho WorkDrive, a cloud storage platform commonly used in India's government sector, has been abused by Mustang Panda as a command channel. The malware uses hardcoded Zoho OAuth credentials to access an attacker-controlled WorkDrive account, allowing the attackers to read commands from an inbox folder and write stolen output to an outbox. This tactic enables the attackers to hide their malicious activity within legitimate cloud traffic, making it more difficult to detect.
Implications and Recommendations
The discovery of these attacks highlights the need for organizations to be proactive in protecting their networks and data. This includes monitoring cloud-based activity, implementing robust security measures, and educating users about the risks of spear-phishing and other social engineering tactics. By understanding the tactics used by groups like Mustang Panda, organizations can better prepare themselves to defend against similar attacks in the future.
Key points
- Mustang Panda is a China-aligned espionage group
- The group is using Zoho WorkDrive as a command channel in attacks
- New malware tools include SHARDLOADER, MINIRECON, and ZOHOMURK
The fact that these attacks have been discovered and attributed to a specific group can help organizations improve their defenses and prevent similar attacks in the future. By sharing information and best practices, the cybersecurity community can work together to stay ahead of threats like Mustang Panda.
The use of legitimate cloud services as a command channel by Mustang Panda highlights the evolving nature of cyber threats and the need for continuous vigilance. If left unchecked, these types of attacks could lead to significant breaches of sensitive information, compromising national security and economic interests.



