Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes — Threadlinqs Intelligence
As of 2026-05-30, Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes is a high-severity apt threat attributed to Mustang Panda (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 47 indicators of compromise.
Threat ID: TL-2026-0184 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Mustang Panda · China · ESPIONAGE
Mustang Panda (Chinese APT) and opportunistic threat actors are weaponizing Middle East conflict themes to deliver the LOTUSLITE backdoor and StealC infostealer via DLL sideloading, CHM files, and
Zscaler ThreatLabz identified a surge of cyber operations exploiting Middle East geopolitical tensions, documenting eight distinct attack cases spanning espionage malware deployment, credential phishing, financial fraud, and cryptocurrency scams. Over 8,000 newly registered domains leveraging conflict themes were identified.
**Case 1 — GCC Region Targeted Attack (March 1, 2026):** A ZIP archive containing a malicious LNK file (photo_2026-03-01_01-20-48.pdf.lnk) uses cURL to download a CHM file from 360printsol.com. The CHM is decompiled via hh.exe, extracting a secondary LNK that copies a decoy PDF about Iranian missile strikes against a US base in Bahrain, extracts a TAR archive to %AppData%, and executes ShellFolder.exe. This triggers DLL sideloading of ShellFolderDepend.dll (32-bit), which checks for Bitdefender's bdagent.exe before establishing persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The loader then decrypts RC4-encrypted shellcode from Shelter.ex using the key "20260301@@@" via the Windows Native API SystemFunction033, allocates memory with VirtualAlloc, and executes the payload.
**Case 2 — LOTUSLITE Backdoor / Mustang Panda (March 4, 2026):** A ZIP archive contains a legitimate KuGou music application binary renamed "Iran Strikes U.S. Military Facilities Across Gulf Region.exe" alongside a malicious libmemobook.dll in a directory named "JCPOA". The executable sideloads libmemobook.dll, which checks for prior installation at C:\ProgramData\CClipboardCm\WebFeatures.exe. If not installed, it copies itself to C:\ProgramData\CClipboardCm\, renames the legitimate binary to SafeChrome.exe, and establishes persistence via the registry key ACboardCm. It then downloads secondary payloads (WebFeatures.exe and kugou.dll) from e-kflower.com. The kugou.dll component is the LOTUSLITE backdoor — a custom C++ implant that communicates with C2 server 172.81.60.97 over TCP 443 using HTTP POST requests with a hardcoded Chrome 143.0.0.0 User-Agent. LOTUSLITE provides system/user enumeration, interactive cmd.exe shell, file manipulation, and periodic beaconing. Code overlap confirms connection to the January 2026 Venezuela-themed LOTUSLITE campaign. A secondary persistence key (ASEdge) is established at C:\ProgramData\WebFeatures\.
**Case 3 — Fake News to StealC Infostealer:** A fake news blog at goldman-iran-krieg.pages.dev performs device fingerprinting and redirects victims to file-hosting sites serving password-protected ZIP archives. The password is displayed on the same page. The archive contains StealC v2 (MD5: 098BC0DD6A02A777FABB1B7D6F2DA505), which communicates with C2 server 80.97.160.190 to exfiltrate browser credentials, cookies, cryptocurrency wallets, and system information.
**Cases 4-8 — Opportunistic Exploitation:** Additional cases include a fake US Social Security Administration portal (cfgomma.com) delivering PDQConnect RMM for remote access, a fake Israeli Kvish 6 toll gateway exfiltrating payment data via Telegram bot, donation scams (irandonation.org) routing payments through suspicious channels, conflict-themed merchandise storefronts (nowarwithiran.store) for payment card harvesting, and a pump-and-dump cryptocurrency scheme via khameneisol.xyz. Persian-language source code comments in cases 4-5 provide attribution indicators toward Iran-aligned actors.
---
**Revalidated on 2026-03-12**
Since the original publication of TL-2026-0184, this threat has been independently corroborated and significantly expanded by at least seven major security vendors (Check Point, Proofpoint, Cisco Talos, Unit 42, Kaspersky, Acronis TRU, IBM X-Force), elevating confidence in both attribution and scope. The most critical development is Check Point Research's March 1, 2026 disclosure confirming Camaro Dragon (Mustang Panda) launched targeted espionage campaigns against Qatari entities within 24 hours of the U.S.-Israel Operation Epic Fury strikes on Iran. The PlugX deployment used configuration key 'qwedf
Weaknesses (CWE)
CWE-426, CWE-494
Target sectors: government, defense, policy-organizations, think-tanks, financial, general-public
Target regions: Middle East, Gulf Cooperation Council, North America, Israel, Bahrain, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 47 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1583, T1587, T1608, T1566, T1566, T1204, T1059, T1106, T1218, T1547