CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Mustang Panda

Malware

SHARDLOADER: DLL Sideloading Malware Loader

SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…

DLL Sideloading loader Mustang Panda SHARDLOADER
June 29, 2026
Malware

MINIRECON: Toneshell Variant Backdoor

MINIRECON is a reworked variant of the Toneshell backdoor, beaconing over WebSocket on HTTPS, used by Mustang Panda.

backdoor MINIRECON Mustang Panda Toneshell
June 29, 2026
Malware

ZOHOMURK: Zoho WorkDrive Dead Drop Malware

ZOHOMURK is a novel malware that uses hardcoded Zoho OAuth credentials to turn an attacker-controlled WorkDrive account into a dead drop for…

dead drop exfiltration Mustang Panda Zoho WorkDrive
June 29, 2026
Malware

Toneshell: Backdoor Malware

Toneshell is a backdoor malware documented by IBM X-Force, used as a base for the MINIRECON variant by Mustang Panda.

backdoor IBM X-Force Mustang Panda Toneshell
June 29, 2026
Malware

LOTUSLITE: Backdoor Malware

LOTUSLITE is a backdoor used by Mustang Panda in attacks on India's banking sector and South Korean policy circles, staged through legitimate…

backdoor banking India LOTUSLITE
June 29, 2026
Attack Groups

Mustang Panda

[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been…

BRONZE PRESIDENT CAMARO DRAGON ClumsyToad EARTH PRETA
May 12, 2026