ZOHOMURK is a Windows implant associated with the China-linked espionage group Mustang Panda. It emerged in 2026 in campaigns targeting Indian government entities and the hydropower sector, including organizations connected to cooperation with Taiwanese institutions. The malware is notable for abusing Zoho WorkDrive as a covert command-and-control and exfiltration channel, allowing attacker traffic to blend with legitimate enterprise cloud activity.
ZOHOMURK authenticates to Zoho using hardcoded OAuth credentials and uses an attacker-controlled WorkDrive account as a dead-drop style control channel. It creates victim-specific folder structures, polls for tasking, removes consumed commands, and uploads execution results back to cloud storage. Reported tasking includes interactive shell access, shell teardown, and file-related operations with response upload. The implant also maintains a heartbeat mechanism that can re-register an infected host if its remote folder structure is removed, improving resilience.
The malware includes anti-analysis behavior, including timing-based checks, and in some variants conditionally avoids persistence when analysis is suspected. Observed persistence mechanisms include execution through DLL sideloading chains involving legitimate signed binaries and establishment of user-level autorun persistence. ZOHOMURK was deployed alongside the SHARDLOADER loader in spearphishing campaigns that delivered compressed archives containing lure material and malicious sideloading components.
Operationally, ZOHOMURK fits Mustang Panda’s long-running espionage tradecraft: politically themed lures, DLL sideloading, abuse of legitimate services, and intelligence collection against government and strategic sectors. Its use of Zoho WorkDrive for remote tasking and exfiltration reflects a shift toward cloud-service abuse to reduce detection while maintaining interactive post-compromise access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Campaign II (MOU / Taiwan) deploys ZOHOMURK, a novel implant that abuses Zoho WorkDrive, a legitimate cloud storage platform widely used in the Indian government sector, for command-and-control, data exfiltration, and remote task execution.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp...
Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp...
Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp...
Both were delivered as ZIP archives, distributed via spearphishing, in which the malicious DLL was marked with the hidden attribute.
Alert on trusted applications (Solid PDF Creator, Microsoft DNX, Citrix components) executing from non-standard paths.
After identifying the environment as an analyst sandbox, the operator attempted to disrupt analysis by deleting tools and corrupting multiple files on the host... the implant removes it from WorkDrive by sending a PATCH request... which moves the file to trash.
Once running, the implant generates a unique victim identifier by combining the hostname... with the system's public IP address... We also observed the operator actively conducting reconnaissance on the infected system.
ZOHOMURK is the most unusual piece of this operation. It carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a covert command channel.
MINIRECON establishes a WebSocket connection over HTTPS using the native WinHTTP API... ZOHOMURK... sends a POST request to accounts.zoho.com/oauth/v2/token... HTTPS traffic to workdrive.zoho.com
ZOHOMURK , a novel implant that abuses Zoho WorkDrive ... for command-and-control, data exfiltration, and remote task execution.
the implant extracts two embedded files from the .rdata section: pcl2bmp.exe, a legitimate signed Citrix Receiver binary, and ctxmui.dll, a malicious DLL... When a new command file is found in the victim's inbox, the implant downloads it to a temporary file named readata.dat on disk.
ZOHOMURK is a newly identified implant that leverages Zoho WorkDrive for command-and-control, data exfiltration and remote task execution... uploads the output back to the outbox for the operator to retrieve.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel cloud-abusing implant used for command-and-control, exfiltration, and remote task execution via Zoho WorkDrive; supports shell access, file operations, and self-healing victim re-registration.
Backdoor or malware component used by Mustang Panda while abusing Zoho WorkDrive for C2 and data exfiltration.
A novel implant used by Mustang Panda that abuses Zoho WorkDrive as covert C2 using hardcoded OAuth credentials, reading commands from cloud folders and exfiltrating stolen data back through the same service.
Novel implant that abuses Zoho WorkDrive as a command-and-control dead drop using hardcoded OAuth credentials to receive commands and exfiltrate stolen data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.