A China-linked hacking group called Mustang Panda has found a clever disguise for its espionage campaigns: legitimate cloud storage. Acronis Threat Research Unit found the group abusing Zoho WorkDrive — a cloud platform widely used across Indian government agencies — to send commands to infected machines and steal data.
The trick is simple but effective. The malicious traffic looks like ordinary cloud storage activity, so it blends right in with legitimate network traffic. Acronis found active compromises inside Indian government networks, including computers used by senior administrative staff, and worked with CERT-In to clean up.
Three new tools were identified. SHARDLOADER sideloads a malicious DLL through legitimately signed binaries — a Solid PDF Creator executable in one campaign and a Citrix Receiver binary in the other. MINIRECON is a variant of the Toneshell backdoor, now communicating over WebSocket connections on HTTPS. Then there’s ZOHOMURK, the most novel piece: it carries hardcoded Zoho OAuth credentials and uses an attacker-controlled WorkDrive account as a dead drop, reading commands from an inbox folder and writing stolen data to an outbox.
Both campaigns arrived as ZIP archives delivered through spear-phishing emails. One lure was themed around a hydropower cooperation proposal, the other around a memorandum of understanding between Indian and Taiwanese institutions. The goal appears to be intelligence on India’s hydropower plans and its defense ties with Taiwan.
Acronis attributes the activity to Mustang Panda with high confidence, citing code overlap with Toneshell, reused infrastructure, and a recurring typo — “RunOnece” — carried across multiple implants. Active beaconing ran from June 12 to June 22, 2026.
There’s no patch for this because it’s abusing a legitimate service. The defense is catching the delivery chain and the cloud abuse. Acronis published indicators including persistence Run keys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and suspicious Zoho user agents from non-browser processes.
