Mustang Panda Uses Zoho WorkDrive in Attacks on Indian Government
The China-aligned Mustang Panda group has launched campaigns targeting Indian government networks and hydropower infrastructure using new malware and Zoho WorkDrive as a command channel. Acronis researchers detected active compromises including high-level administrative systems.
Why it matters
This highlights advanced persistent threat actors exploiting legitimate cloud services for covert command and control.
SOC impact
SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.
Recommended actions
- Determine whether affected users, domains, or third-party providers intersect with your organization.
- Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
- Review MFA coverage and initiate credential resets where exposure is confirmed.
Executive Summary
The China-aligned Mustang Panda group has launched campaigns targeting Indian government networks and hydropower infrastructure using new malware and Zoho WorkDrive as a command channel. Acronis researchers detected active compromises including high-level administrative systems. This highlights advanced persistent threat actors exploiting legitimate cloud services for covert command and control.
SOC Impact
SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.
Credential and Exposure Checks
- Determine whether affected users, domains, or third-party providers intersect with your organization.
- Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
- Review MFA coverage and initiate credential resets where exposure is confirmed.
Why It Matters
This highlights advanced persistent threat actors exploiting legitimate cloud services for covert command and control.