discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

Mustang Panda, a China-aligned espionage group, is using Zoho WorkDrive as a command channel in attacks on the Indian government and hydropower targets. The group is deploying new malware and abusing the legitimate cloud service to pass commands and exfiltrate data.

By Ravie Lakshmanan·Jun 29·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
Image: thehackernews.com

The attacks involve the use of new malware tools, including SHARDLOADER, MINIRECON, and ZOHOMURK, which are designed to evade detection and exploit the trust placed in legitimate cloud services.

Why it matters

The attacks highlight the growing threat of cyber espionage and the need for organizations to be vigilant in protecting their networks and data. The use of legitimate cloud services as a command channel also underscores the importance of monitoring and securing cloud-based activity.

Imagine you have a safe box where you store important documents. Now, imagine someone finds a way to open that safe box without you knowing, and they use it to send and receive secret messages. That's kind of what's happening here, but instead of a safe box, it's a cloud storage service that's being used by hackers to steal information.

Analysis

Introduction to Mustang Panda's Tactics

The China-aligned espionage group Mustang Panda has been identified as the perpetrator of a series of attacks on the Indian government and hydropower targets. The group's tactics involve the use of new malware tools, including SHARDLOADER, MINIRECON, and ZOHOMURK, which are designed to evade detection and exploit the trust placed in legitimate cloud services.

The Role of Zoho WorkDrive in the Attacks

Zoho WorkDrive, a cloud storage platform commonly used in India's government sector, has been abused by Mustang Panda as a command channel. The malware uses hardcoded Zoho OAuth credentials to access an attacker-controlled WorkDrive account, allowing the attackers to read commands from an inbox folder and write stolen output to an outbox. This tactic enables the attackers to hide their malicious activity within legitimate cloud traffic, making it more difficult to detect.

Implications and Recommendations

The discovery of these attacks highlights the need for organizations to be proactive in protecting their networks and data. This includes monitoring cloud-based activity, implementing robust security measures, and educating users about the risks of spear-phishing and other social engineering tactics. By understanding the tactics used by groups like Mustang Panda, organizations can better prepare themselves to defend against similar attacks in the future.

Key points

  • Mustang Panda is a China-aligned espionage group
  • The group is using Zoho WorkDrive as a command channel in attacks
  • New malware tools include SHARDLOADER, MINIRECON, and ZOHOMURK
The Upside

The fact that these attacks have been discovered and attributed to a specific group can help organizations improve their defenses and prevent similar attacks in the future. By sharing information and best practices, the cybersecurity community can work together to stay ahead of threats like Mustang Panda.

The Downside

The use of legitimate cloud services as a command channel by Mustang Panda highlights the evolving nature of cyber threats and the need for continuous vigilance. If left unchecked, these types of attacks could lead to significant breaches of sensitive information, compromising national security and economic interests.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycyber-espionagemalwarecloud-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 29, 2026

Source

thehackernews.com

Share

Topics

securitycyber-espionagemalwarecloud-security

Related

More from this desk

Aug 14·bleepingcomputer.com

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

The article discusses the evolving attack chain in Google Workspace security, where OAuth tokens become the entry point for attackers, and AI agents are increasingly used to exploit vulnerabilities. The author argues that security teams need to rethink their defenses to a…

Aug 14·bleepingcomputer.com

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.

Aug 14·bleepingcomputer.com

Shell investigates 'potential incident' after Clop data theft claims

Oil giant Shell is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. The allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.

Aug 14·krebsonsecurity.com

Who’s Tracking You? Use This New Service to Find Out

A new service called DecryptAds scrapes and correlates adtech data to reveal the entities tracking users. The service makes it easy to learn about the adtech companies and data brokers that may run ads or harvest data from websites and apps.