CyberSecurityBoardThreat Intel · CVEs · Products

Category: Malware

Malware families, payloads, loaders, ransomware and related tooling.

Malware

SHARDLOADER: DLL Sideloading Malware Loader

SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…

DLL Sideloading loader Mustang Panda SHARDLOADER
June 29, 2026
Malware

MINIRECON: Toneshell Variant Backdoor

MINIRECON is a reworked variant of the Toneshell backdoor, beaconing over WebSocket on HTTPS, used by Mustang Panda.

backdoor MINIRECON Mustang Panda Toneshell
June 29, 2026
Malware

ZOHOMURK: Zoho WorkDrive Dead Drop Malware

ZOHOMURK is a novel malware that uses hardcoded Zoho OAuth credentials to turn an attacker-controlled WorkDrive account into a dead drop for…

dead drop exfiltration Mustang Panda Zoho WorkDrive
June 29, 2026
Malware

Toneshell: Backdoor Malware

Toneshell is a backdoor malware documented by IBM X-Force, used as a base for the MINIRECON variant by Mustang Panda.

backdoor IBM X-Force Mustang Panda Toneshell
June 29, 2026
Malware

LOTUSLITE: Backdoor Malware

LOTUSLITE is a backdoor used by Mustang Panda in attacks on India's banking sector and South Korean policy circles, staged through legitimate…

backdoor banking India LOTUSLITE
June 29, 2026
Malware

ShadowPad Backdoor

A modular backdoor malware previously hosted on the same staging server used in the Thai Ministry of Finance attack. It is known…

backdoor malware ShadowPad
June 29, 2026
Malware

PteroSand: Gamaredon Malware Payload

PteroSand is a malware payload delivered by Gamaredon via HTA downloaders in spear-phishing campaigns targeting Ukraine.

Gamaredon HTA downloader malware PteroSand
June 29, 2026