Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators India's government and energy sectors targeted with ZOHOMURK and MINIRECON

www.zohoapis.com

TLP:CLEAR
Active

Domain

Description

Mustang Panda orchestrated two concurrent espionage campaigns targeting Indian government entities and hydropower infrastructure between May and June 2026. The campaigns leveraged DLL sideloading via legitimate executables to deploy newly identified malware including SHARDLOADER, MINIRECON, and ZOHOMURK. MINIRECON represents an evolution of Toneshell with WebSocket-based command-and-control capabilities, while ZOHOMURK abuses Zoho WorkDrive cloud services for C2 communications and data exfiltration. Distribution occurred through spear-phishing with lures themed around India-Taiwan cooperation agreements and hydropower projects. The activity demonstrates code overlaps with previous tooling, infrastructure proximity to known operations, and targeting patterns aligned with Chinese strategic intelligence collection priorities. Multiple compromised government systems were identified, with coordination conducted through CERT-In for victim notification and remediation.

Sightings (0)

No sightings recorded yet

Details

Name / Label
India's government and energy sectors targeted with ZOHOMURK and MINIRECON
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 15:12
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of www.zohoapis.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.