LOTUSLITE is a custom Windows backdoor associated with the China-linked espionage group Mustang Panda. It has been used in targeted campaigns against U.S. government and policy organizations, Indian financial institutions, South Korean policy circles, and diplomatic or government-related entities. The malware is positioned for intelligence collection and long-term access rather than financial theft, and has been observed in lures tied to current geopolitical events as well as regionally tailored themes such as banking-sector content.
LOTUSLITE is commonly deployed through DLL sideloading using legitimate signed executables, including Microsoft-signed binaries and software associated with KuGou or other benign applications. Reported delivery chains include spearphishing and phishing lures delivered in archives or CHM files that contain a legitimate executable alongside a malicious DLL. In some campaigns, the lure content impersonated trusted institutions or public-policy figures, and cloud-hosted staging was also used.
Functionally, LOTUSLITE provides remote shell access, file enumeration and manipulation, session management, and host profiling. Variants have been documented establishing persistence through user-level autorun mechanisms and then communicating with command-and-control infrastructure over HTTPS. The malware uses runtime API resolution, dynamic loading, string obfuscation or decryption, and traffic masquerading techniques to complicate analysis and blend with normal web activity. Multiple reports also describe anti-analysis checks tied to execution context and command-line arguments. Newer variants modified protocol markers and internal command structures, indicating active maintenance and iterative development.
Operational reporting consistently links LOTUSLITE to Mustang Panda based on overlapping infrastructure, delivery tradecraft, code lineage, and recurring operational patterns. The malware forms part of Mustang Panda’s broader post-PlugX tooling evolution and has been used as a reusable espionage implant across multiple regional targeting sets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group is deploying an updated version of the LOTUSLITE backdoor (v1.1) that uses legitimate Microsoft-signed executables to bypass security checks and gain persistent access to victim systems.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware communicates with a dynamic DNS-based C2 over HTTPS and enables remote shell access, file operations, and session control, indicating espionage-driven objectives.
external.ExecuteShellCommand() calls powershell.exe with: -ExecutionPolicy Bypass -WindowStyle Hidden Downloads svchost.exe, executes from %TEMP% hidden.
0x0A CMD_SPAWN_SHELL Creates anonymous stdin/stdout pipes and spawn a hidden cmd.exe process with redirected handles
LOTUSLITE: A backdoor that has appeared in campaigns targeting government institutions, financial organizations, and diplomatic entities. Its delivery methods have evolved from CHM files to JavaScript loaders and DLL sideloading.
When a user clicked the file, it triggered a chain of events that downloaded a malicious JavaScript payload called music.js from the domain cosmosmusic[.]com.
The starting point of the attack is a Compiled HTML (CHM) file embedding the malicious payloads – a legitimate executable and a rogue DLL – along with an HTML page that contains a pop-up which prompts the user to click "Yes."
The malware resolves all imports in runtime by decrypting the function and DLL names with using a two-phase algorithm: XOR decryption with a rotating 5-byte key ... In-place reversal of the decrypted result
Runtime API resolution: The malware now resolves APIs through ntdll.dll chains, making static analysis more difficult.
All WinINet, kernel32, shell, and process APIs are resolved at runtime via a PEB walk mechanism.
The malware also created fake pop-up windows designed to look like real HDFC Bank software. While victims believed they were interacting with a banking app, the LOTUSLITE backdoor was silently establishing a foothold on their systems.
The analyzed sample is a fully-featured Windows backdoor DLL disguised as a WPS Office component ... masquerading as a legitimate Microsoft runtime library.
MITRE ATT&CK Coverage ... Defense Evasion Dynamic-link Library Injection T1055 Delivered as DLL
Numerous strings are decrypted on the fly, making generic identification of the implant significantly more difficult.
MITRE ATT&CK Coverage ... Defense Evasion Indirect Command Execution T1202 API resolution hides imports
If both conditions are met, it fingerprints the machine and prepares a buffer as follows: [USERNAME]|[COMPUTERNAME]
Host Discovery Initial beacon includes basic victim identification data such as computer name and username.
The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations and session management.
LOTUSLITE communicates exclusively over HTTPS on port 443 , using WinINet APIs resolved dynamically at runtime. All traffic is POST-based
The HTTP connection is initialized while spoofing a Microsoft domain: POST https://forms.microsoft.com/info/faq/v6 ... Host: forms.microsoft.com
0x0E CMD_WRITE_FILE Accepts a payload formatted as filename\0data ... opens the target file in append mode ... and writes the supplied data blob using fwrite . Used for dropping or appending files to disk.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Middle East Conflict Cyber Threats: LOTUSLITE Backdoor, StealC, Phishing, and Meme-Coin Scams
A backdoor used by Mustang Panda in campaigns against government, finance, and diplomatic targets; delivered via CHM files, JavaScript loaders, and DLL sideloading.
A malware tool previously linked by Acronis to Mustang Panda in earlier campaigns targeting India’s banking sector and South Korean policy circles.
Backdoor previously linked by Acronis to Mustang Panda attacks on India's banking sector and South Korean policy targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.