Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK — Threadlinqs Intelligence
As of 2026-09-02, Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK is a high-severity apt threat attributed to Mustang Panda (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-2293 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Mustang Panda · China · ESPIONAGE
Acronis TRU, working with CERT-In, uncovered two concurrent Mustang Panda espionage campaigns against Indian government and hydropower-sector entities. Hydropower-cooperation and India-Taiwan-MOU
Between June 12 and June 22, 2026, Acronis Threat Research Unit (TRU) observed two concurrent, technically related espionage intrusion sets against Indian government and hydropower-sector networks, attributed with high confidence to the China-aligned threat actor Mustang Panda (also tracked as TA416, RedDelta, Bronze President, Stately Taurus, Camaro Dragon, Earth Preta, Hive0154, Twill Typhoon, and ITG27/Hive0154 by IBM X-Force). Both campaigns began with spear-phishing ZIP archives — one themed as a hydropower-cooperation proposal, the other around an India-Taiwan memorandum of understanding — that conceal a malicious DLL alongside a legitimate, signed decoy executable. Running the signed binary (a repackaged 'Hydropower Cooperation Project Proposal.exe' in campaign one, a Citrix Receiver pcl2bmp.exe utility in campaign two) side-loads the malicious DLL (SolidPDFCreator.dll / pl2bmpax.dll in campaign one; ctxmui.dll / txMuiApp.dll in campaign two), which is the SHARDLOADER first-stage loader.
SHARDLOADER stages its payload from a hidden directory it creates at C:\ProgramData\IDM\logs, copying the legitimate executable and malicious DLL there. It reconstructs an obfuscated shellcode stub that has been fragmented across .rdata constants using rolling XOR and byte-reordering, allocates executable memory, and triggers execution via an EnumSystemLocalesA callback — a reflective, in-memory loading technique that avoids dropping the final payload to disk in cleartext. Persistence is established via a scheduled task named SolidPDFPcl2Bmp and a registry Run-key value consistently misspelled 'RunOnece' across both campaigns and prior Mustang Panda intrusions, an operational-security lapse that supports attribution.
SHARDLOADER deploys one of two second-stage implants. MINIRECON is a reworked variant of Mustang Panda's long-running Toneshell backdoor family (tracked by IBM X-Force since at least Q1 2021), functioning as a reverse-shell implant that beacons over a WebSocket connection tunneled through HTTPS via WinHTTP, disables TLS certificate validation, accepts self-signed certificates, and includes proxy fallback logic; it calls back to couldinstallup[.]com, which resolves to 199.209.141.166 — an IP block IBM X-Force has previously tied to Mustang Panda infrastructure. ZOHOMURK is a novel cloud-abusing implant that carries hardcoded Zoho OAuth credentials for an attacker-controlled Zoho WorkDrive account, using it as a command-and-control dead drop: the implant polls an 'inbox' folder for tasking, executes commands locally, and writes results/exfiltrated data to an 'outbox' folder, disguising its C2 traffic as legitimate cloud-sync activity via spoofed User-Agent strings ('Zoho Client/1.0', 'IPFetcher/1.0') and multipart POST requests, plus timing-based anti-analysis checks.
Victims included Indian government networks — including machines belonging to senior administrative personnel — and organizations in India's hydropower sector, consistent with an intelligence-collection objective around India's hydropower infrastructure and its defense/cooperation relationship with Taiwan. The activity followed an earlier April 2026 Mustang Panda campaign that used the LOTUSLITE tool against India's banking sector, indicating sustained targeting of India across sectors in 2026. Acronis TRU coordinated notification and remediation with India's CERT-In. Attribution to Mustang Panda is assessed at high confidence based on reuse of the Solid PDF Creator side-loading chain from prior campaigns, code overlaps with the established Toneshell family, C2 infrastructure geographically/AS-block correlated with prior IBM X-Force Mustang Panda tracking, the recurring 'RunOnece' misspelling across implants, and generally thin operational security (hardcoded OAuth tokens, plaintext identifiers).
Target sectors: government administration, energy
Target regions: South Asia, india
Timeline
- Mustang Panda deploys the LOTUSLITE tool against India's banking sector, an earlier 2026 campaign preceding the SHARDLOADER/MINIRECON/ZOHOMURK operations and indicating sustained multi-sector targeting of India.
- Acronis TRU begins observing active beaconing from compromised Indian government systems, including machines belonging to senior administrative personnel.
- The observed active-beaconing window from compromised Indian government and hydropower-sector systems ends.
- Acronis TRU coordinates with India's CERT-In on victim notification and remediation for the compromised government systems.
- The Hacker News publishes coverage of the campaign, citing Acronis TRU's findings and CERT-In coordination.
- GBHackers publishes an additional technical writeup detailing SHARDLOADER's shellcode-reconstruction and execution mechanics along with sample hashes.
- SOCPrime publishes an extended technical and detection-oriented analysis of the ZOHOMURK/MINIRECON campaign.
References
- Mustang Panda targets India's government and energy sectors with SHARDLOADER, MINIRECON, and ZOHOMURK
- Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
- Mustang Panda Targets India with ZOHOMURK and MINIRECON
- Mustang Panda Targets India's Government and Energy Sectors With SHARDLOADER, MINIRECON, and ZOHOMURK
- Mustang Panda Abuses Zoho WorkDrive for Command-and-Control and Exfiltration
- Mustang Panda Exploits Zoho WorkDrive in Indian Government Attack
- Mustang Panda (China-aligned) — CrowdStrike CQL Threat-Hunt Queries: ZOHOMURK/MINIRECON
- Trapping a Mustang Panda
- Latest Mustang Panda Arsenal: ToneShell and StarProxy
- Mustang Panda, TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, Group G0129
- TONESHELL, Software S1239
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1059, T1547, T1053, T1574, T1620, T1140, T1036, T1071, T1573