Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes
Mustang Panda LOTUSLITE Backdoor & StealC Campaigns (TL-2026-0184), also tracked as Operation Middle East Storm, is a high-severity advanced persistent threat campaign, first published 2026-03-06. It is attributed to Mustang Panda (China) with medium confidence, affects Multiple Windows Endpoints, maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 47 indicators of compromise.
Key facts for TL-2026-0184
- Threat ID
- TL-2026-0184
- Also known as
- Operation Middle East Storm, LOTUSLITE Middle East Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-06
- Last reviewed
- 2026-03-06
- Attribution
- Mustang Panda
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, defense, policy-organizations, think-tanks, financial, general-public
- Target regions
- Middle East, Gulf Cooperation Council, North America, Israel, Bahrain, Global
- Detection rules
- 9
- Indicators of compromise
- 47
Malware and tooling in Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
Malware and tooling: LOTUSLITE, ShellFolderDepend.dll loader, Stealc, LOTUSLITE HTTP C2, PDQ Connect
Mustang Panda (Chinese APT) and opportunistic threat actors are weaponizing Middle East conflict themes to deliver the LOTUSLITE backdoor and StealC infostealer via DLL sideloading, CHM files, and malicious LNK shortcuts. Over 8,000 newly registered conflict-themed domains have been identified. Multiple active multi-stage attack chains with concrete C2 infrastructure (172.81.60.97, 80.97.160.190) were observed as of March 2026.
How Mustang Panda LOTUSLITE Backdoor & StealC Campaigns works
Zscaler ThreatLabz identified a surge of cyber operations exploiting Middle East geopolitical tensions, documenting eight distinct attack cases spanning espionage malware deployment, credential phishing, financial fraud, and cryptocurrency scams. Over 8,000 newly registered domains leveraging conflict themes were identified.
**Case 1 — GCC Region Targeted Attack (March 1, 2026):** A ZIP archive containing a malicious LNK file (photo_2026-03-01_01-20-48.pdf.lnk) uses cURL to download a CHM file from 360printsol.com. The CHM is decompiled via hh.exe, extracting a secondary LNK that copies a decoy PDF about Iranian missile strikes against a US base in Bahrain, extracts a TAR archive to %AppData%, and executes ShellFolder.exe. This triggers DLL sideloading of ShellFolderDepend.dll (32-bit), which checks for Bitdefender's bdagent.exe before establishing persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The loader then decrypts RC4-encrypted shellcode from Shelter.ex using the key "20260301@@@" via the Windows Native API SystemFunction033, allocates memory with VirtualAlloc, and executes the payload.
**Case 2 — LOTUSLITE Backdoor / Mustang Panda (March 4, 2026):** A ZIP archive contains a legitimate KuGou music application binary renamed "Iran Strikes U.S. Military Facilities Across Gulf Region.exe" alongside a malicious libmemobook.dll in a directory named "JCPOA". The executable sideloads libmemobook.dll, which checks for prior installation at C:\ProgramData\CClipboardCm\WebFeatures.exe. If not installed, it copies itself to C:\ProgramData\CClipboardCm\, renames the legitimate binary to SafeChrome.exe, and establishes persistence via the registry key ACboardCm. It then downloads secondary payloads (WebFeatures.exe and kugou.dll) from e-kflower.com. The kugou.dll component is the LOTUSLITE backdoor — a custom C++ implant that communicates with C2 server 172.81.60.97 over TCP 443 using HTTP POST requests with a hardcoded Chrome 143.0.0.0 User-Agent. LOTUSLITE provides system/user enumeration, interactive cmd.exe shell, file manipulation, and periodic beaconing. Code overlap confirms connection to the January 2026 Venezuela-themed LOTUSLITE campaign. A secondary persistence key (ASEdge) is established at C:\ProgramData\WebFeatures\.
**Case 3 — Fake News to StealC Infostealer:** A fake news blog at goldman-iran-krieg.pages.dev performs device fingerprinting and redirects victims to file-hosting sites serving password-protected ZIP archives. The password is displayed on the same page. The archive contains StealC v2 (MD5: 098BC0DD6A02A777FABB1B7D6F2DA505), which communicates with C2 server 80.97.160.190 to exfiltrate browser credentials, cookies, cryptocurrency wallets, and system information.
**Cases 4-8 — Opportunistic Exploitation:** Additional cases include a fake US Social Security Administration portal (cfgomma.com) delivering PDQConnect RMM for remote access, a fake Israeli Kvish 6 toll gateway exfiltrating payment data via Telegram bot, donation scams (irandonation.org) routing payments through suspicious channels, conflict-themed merchandise storefronts (nowarwithiran.store) for payment card harvesting, and a pump-and-dump cryptocurrency scheme via khameneisol.xyz. Persian-language source code comments in cases 4-5 provide attribution indicators toward Iran-aligned actors.
---
**Revalidated on 2026-03-12**
Since the original publication of TL-2026-0184, this threat has been independently corroborated and significantly expanded by at least seven major security vendors (Check Point, Proofpoint, Cisco Talos, Unit 42, Kaspersky, Acronis TRU, IBM X-Force), elevating confidence in both attribution and scope. The most critical development is Check Point Research's March 1, 2026 disclosure confirming Camaro Dragon (Mustang Panda) launched targeted espionage campaigns against Qatari entities within 24 hours of the U.S.-Israel Operation Epic Fury strikes on Iran. The PlugX deployment used configuration key 'qwedfgx202211' and RC4 decryption key '20260301@@@' — the identical key format documented in the original Zscaler Case 1 GCC region attack — providing high-confidence attribution and confirming the same operator cluster executed both campaigns. Proofpoint's parallel discovery of UNK_InnerAmbush (assessed China-aligned) targeting Middle Eastern government organizations with identical lure themes (Bahrain base attacks, Gulf oil/gas facilities) further validates the original threat intelligence.
Mustang Panda's operational tempo in late 2025 through early 2026 demonstrates a deliberate post-PlugX-takedown retooling: after the FBI/DOJ January 2025 disruption of 4,258 PlugX-infected U.S. systems, the group rapidly deployed LOTUSLITE (January 2026, U.S. policy targets), updated COOLCLIENT with browser stealers (January 2026, Southeast Asian governments), a kernel-mode rootkit for ToneShell (December 2025, Asian targets), and SnakeDisk USB worm with geofenced Yokai backdoor (August 2025, Thailand). The March 2026 pivot to Middle East conflict exploitation represents the latest in this accelerating operational cadence.
New IOCs from Check Point include C2 IPs 185.219.220.73 and 91.193.17.117, domain almersalstore[.]com, and 10 file hashes. Proofpoint contributed C2 domain support.almersalstore[.]com and tracking infrastructure at deepdive.hypernas[.]com. Kaspersky added COOLCLIENT hashes (F518D8E5FE70D9090F6280C68A95998F loader, browser stealer variants A/B/C), C2 domains account.hamsterxnxx[.]com and japan.Lenovoappstore[.]com, and FTP exfiltration server 113.23.212.15. The StealC campaign (original Case 3) remains active with C2 at 80.97.160.190 and distribution via conflict-themed fake news domains including goldman-iran-krieg[.]pages[.]dev.
Detection coverage should be updated to include: PlugX with key 'qwedfgx202211' config detection, NVDA screen reader DLL sideloading (nvdaHelperRemote.dll), COOLCLIENT browser stealer output at C:\Users\Public\Libraries\License.txt, Baidu NetDisk binary sideloading, kernel-mode rootkit driver registration as minifilter (ProjectConfiguration.sys), and SnakeDisk USB propagation patterns. The MITRE ATT&CK mapping should be expanded to include T1014 (Rootkit), T1091 (Replication Through Removable Media), T1036.007 (Double File Extensions), and T1480 (Execution Guardrails/Geofencing).
MITRE ATT&CK techniques used in TL-2026-0184
collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
stealth
T1218 System Binary Proxy Execution
persistence
T1547 Boot or Logon Autostart Execution; T1574 Hijack Execution Flow
credential-access
T1555 Credentials from Password Stores
initial-access
resource-development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities
Affected products and versions in Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
- Multiple — Windows Endpoints
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016+ - Tencent — KuGou Music (legitimate binary abused for DLL sideloading)
Vulnerable versions: Multiple versions - Baidu — BaiduNetdisk / ShellFolder.exe (legitimate binary abused for DLL sideloading)
Vulnerable versions: Multiple versions
Remediation for Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
Immediate actions
- Block C2 IPs 172.81.60.97 and 80.97.160.190 at perimeter firewall
- Block all identified malicious domains at DNS/proxy level
- Hunt for DLL sideloading indicators: ShellFolderDepend.dll, libmemobook.dll, kugou.dll in AppData and ProgramData
- Search for persistence registry keys: BaiNetdisk, ACboardCm, ASEdge under HKCU Run
- Quarantine any files matching published hashes
Workarounds
- Block execution of hh.exe (CHM decompilation) via AppLocker policy
- Restrict cURL execution from user context
- Monitor and alert on files with double extensions (.pdf.lnk)
Longer-term hardening
- Deploy EDR with DLL sideloading detection and behavioral analysis
- Implement application whitelisting to prevent unsigned DLL execution
- Enable enhanced logging for registry modifications and DLL loading events
- Conduct user awareness training on conflict-themed phishing lures
- Monitor for Chrome 143.0.0.0 User-Agent strings in outbound HTTP traffic
- Implement DNS sinkholing for newly registered domains
Weaknesses (CWE) in Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
CWE-426, CWE-494
Timeline of Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
Showing the 20 most recent tracked events.
- IBM X-Force discovers SnakeDisk USB worm deployed by Mustang Panda (Hive0154) targeting Thailand-based IP addresses, delivering Yokai backdoor via DLL sideloading with geofencing to TH country code only. [Source: https://www.ibm.com/think/x-force/hive0154-drops-updated-toneshell-backdoor]
- Mustang Panda retools with LOTUSLITE backdoor and SnakeDisk USB worm after PlugX infrastructure takedown
- Kaspersky reports Mustang Panda deploying signed kernel-mode rootkit driver (ProjectConfiguration.sys, signed by Guangzhou Kingteller Technology) to load ToneShell backdoor variant against Asian government targets, first observed use of kernel-mode injection for ToneShell. [Source: https://securelist.com/honeymyte-kernel-mode-rootkit/118590/]
- Venezuela-themed LOTUSLITE spearphishing campaign detected — ZIP archive ''US now deciding what''s next for Venezuela.zip'' uploaded to public malware analysis service, targeting U.S. government and policy organizations via DLL sideloading of KuGou music binary. [Source: https://www.acronis.com/en/tru/posts/lotuslite-targeted-espionage-leveraging-geopolitical-themes/]
- Acronis Threat Research Unit publishes full LOTUSLITE backdoor analysis with C2 at 172.81.60.97 (Dynu Systems, Phoenix AZ), documenting cmd.exe shell spawning, file operations, and Googlebot User-Agent masquerading for C2 beaconing on TCP 443. [Source: https://www.acronis.com/en/tru/posts/lotuslite-targeted-espionage-leveraging-geopolitical-themes/]
- LOTUSLITE first deployed targeting US government and policy organizations via Venezuela-themed spear phishing (ZIP: 'US now deciding what's next for Venezuela.zip')
- Kaspersky publishes analysis of updated COOLCLIENT backdoor with three new browser stealer variants (Chrome, Edge, Chromium) and PowerShell/batch script data exfiltration tools, targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan. [Source: https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/]
- Multiple security vendors (Hacker News, ThaiCERT, PolySwarm) publish analysis of LOTUSLITE Venezuela campaign with C2 172.81.60.97
- U.S. and Israel launch Operation Epic Fury / Operation Roaring Lion strikes against Iran, triggering massive surge in conflict-themed cyber exploitation. Iranian internet drops to 1-4% connectivity. [Source: https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/]
- Proofpoint identifies China-aligned cluster UNK_InnerAmbush targeting Middle Eastern government/diplomatic organizations using Khamenei death lures and Gulf infrastructure attack themes, delivering Cobalt Strike via NVDA screen reader DLL sideloading with C2 at support.almersalstore[.]com. [Source: https://www.proofpoint.com/us/blog/threat-insight/iran-conflict-drives-heightened-espionage-activity-against-middle-east-targets]
- Check Point Research observes Camaro Dragon (Mustang Panda) launching targeted campaigns against Qatari entities using conflict-themed archives, deploying PlugX with configuration key ''qwedfgx202211'' and decryption key ''20260301@@@'' via Baidu NetDisk DLL sideloading. [Source: https://blog.checkpoint.com/research/china-nexus-activity-against-qatar-observed-amid-expanding-regional-tensions/]
- GCC region targeted attack launched using conflict-themed LNK file (photo_2026-03-01_01-20-48.pdf.lnk) delivering CHM-based multi-stage loader via 360printsol.com
- Zscaler ThreatLabz identifies Middle East conflict-themed ZIP archive delivering LOTUSLITE backdoor (Case 2), confirming Mustang Panda pivoted the same tooling from Venezuela themes to Iran conflict themes within two months. [Source: https://www.zscaler.com/blogs/security-research/middle-east-conflict-fuels-opportunistic-cyber-attacks]
- Mustang Panda pivots LOTUSLITE campaign to Middle East conflict themes, deploying via renamed KuGou binary ('Iran Strikes U.S. Military Facilities Across Gulf Region.exe') with libmemobook.dll sideloading
- Over 8,000 newly registered conflict-themed domains identified exploiting Middle East geopolitical tensions for phishing, scams, and malware delivery
- StealC v2 infostealer observed distributed via fake news blog (goldman-iran-krieg.pages.dev) with device fingerprinting and password-protected ZIP delivery, C2 at 80.97.160.190
- Zscaler ThreatLabz publishes comprehensive analysis documenting eight distinct attack cases across espionage, phishing, fraud, and crypto scams
- 149 hacktivist DDoS attacks hit 110 organizations across 16 countries documented; Keymous+ and DieNet drive 70% of attacks. 12 groups active including NoName057(16). Kuwait, Israel, Jordan account for 76% of incidents. [Source: https://thehackernews.com/2026/03/149-hacktivist-ddos-attacks-hit-110.html]
- Cisco Talos publishes updated Middle East situation assessment noting MuddyWater (Seedworm) targeting U.S. banks, airports, nonprofits with novel Dindoor, Fakeset, and Darkcomp backdoors, while Chinese APTs exploit same conflict themes for parallel espionage. [Source: https://blog.talosintelligence.com/talos-developing-situation-in-the-middle-east/]
- As of 2026-05-29, TL-2026-0184 remains ACTIVE: Mustang Panda is confirmed by The Hacker News/Zscaler to be actively refining LOTUSLITE, expanding in April 2026 to India banking and South Korea policy targets. No CVE (espionage TTP-based), no C2 takedowns reported, and new active C2 domains identified, so the actor is operational, not disrupted.
Sources cited for Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
- Zscaler ThreatLabz: Middle East Conflict Fuels Opportunistic Cyber Attacks
- Picus Security: Mustang Panda LOTUSLITE, SnakeDisk, and ToneShellws Campaign
- The Hacker News: LOTUSLITE Backdoor Targets US Policy Entities
- Acronis TRU: LOTUSLITE Targeted Espionage Leveraging Geopolitical Themes
- PolySwarm Blog: Mustang Panda's LotusLite Backdoor
- CYFIRMA Weekly Intelligence Report — January 2026
- ThaiCERT: Mustang Panda Uses Venezuela-Related Lures for LOTUSLITE
- Rescana: LOTUSLITE Campaign Analysis
- MITRE ATT&CK: Mustang Panda (G0129)
- Picus Security: StealC V2 Malware Analysis
Threats related to Mustang Panda LOTUSLITE Backdoor & StealC Campaigns
- Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026)
- Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)
- Open-Source/Freeware Impersonation + Click-Hijacking TDS Ecosystem Delivering RemusStealer, AnimateClipper & SessionGate
- Fake Microsoft Teams Sites Deliver ValleyRAT via NSIS Installer and DLL Sideloading of Tencent GameBox.exe (Silver Fox APT)
- APT Spear-Phishing Campaign Targeting South Korean Entities (April 2026) — LNK/PowerShell Loaders, AutoIt, XenoRAT, Infostealers/Keyloggers/Backdoors
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD
Detection coverage for TL-2026-0184
As of 2026-03-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0184 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.