Mustang Panda Turns Zoho WorkDrive Into C2 in Twin Campaigns Against Indian Government

The China-aligned crew is running parallel operations against New Delhi ministries and hydropower operators, routing commands through a legitimate cloud collaboration service that most enterprise defenses will never flag.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Mustang Panda Turns Zoho WorkDrive Into C2 in Twin Campaigns Against Indian Government
Share

Key points

  • Acronis Threat Research Unit found Mustang Panda actively compromising Indian government networks and hydropower operators.
  • Commands and stolen data travel over Zoho WorkDrive, a legitimate file-sharing service widely used inside Indian government.
  • New malware variants and loaders are deployed alongside the group's established tradecraft.
  • Blocking WorkDrive wholesale is not a viable defense where the service is sanctioned.
  • India's CERT-In had not published a public advisory at time of writing.

Mustang Panda is back inside Indian government networks, and the command channel is hiding in plain sight.

What did Acronis find?

Researchers at Acronis Threat Research Unit identified two active campaigns: one against Indian government offices, a second against hydropower operators. The intrusions reached machines used by senior administrative staff, and Acronis says coordinated remediation is underway.

The group, also tracked as Earth Preta and Bronze President, has been running since at least 2017. Its focus is long-running collection against governments, NGOs, and infrastructure operators across South and Southeast Asia, Europe, and the broader Indo-Pacific. PlugX and Korplug are its established tools. The current wave adds new variants and refreshed loaders, meaning the operators are still actively developing their kit.

How is WorkDrive being used as C2?

Instead of standing up attacker-controlled servers that defenders can blocklist, Mustang Panda is routing tasking and exfiltration through Zoho WorkDrive, a legitimate enterprise file-sharing service. Traffic looks like routine SaaS usage. For networks where Zoho products are already in common government use, that traffic blends in by design.

Abusing trusted cloud platforms for command-and-control (C2, the channel through which attackers direct malware and receive stolen data) is not new. Dropbox and OneDrive have been turned to the same purpose by other groups. What the WorkDrive choice signals is operational judgment: pick the tool your target already allows. Mustang Panda's pivot here is disciplined, not creative.

We've tracked this group across three stories since late June, including the 26 June report on CL-STA-1062 intrusions that also targeted state-owned energy and government entities across the region, and the pattern is consistent: Chinese-nexus operators are systematically upgrading tradecraft to reduce the footprint defenders can see.

Why hydropower?

The targeting fits Beijing's regional posture. Hydropower is a politically sensitive sector along contested river systems shared with India. Government administrative staff offer access to internal correspondence and credentials that can pivot deeper into ministry networks. Neither target is casual.

Acronis describes active compromises, not residual artifacts. At least some of the access was live at the point of discovery. Initial access likely followed the group's established pattern: spear-phishing with lure documents themed to diplomatic affairs, combined with DLL sideloading via signed binaries. The current wave appears consistent with that tradecraft, though Acronis had not published its full indicator set at time of writing.

Should defenders worry about legitimate SaaS being used this way?

Yes, and the WorkDrive case sharpens why. Blocking the service outright is rarely viable when it's sanctioned for business use. Detection has to move to behavioral signals: anomalous API calls from endpoints with no legitimate reason to access WorkDrive programmatically, unusual child processes spawned by office applications, and DLL loads from non-standard paths.

This is espionage, not extortion. No ransom demand, no leak site, no public claim. The goal is dwell time and quiet collection. That makes it harder to detect, slower to attribute, and rarely newsworthy until the damage is already done.

New Delhi is firmly on Mustang Panda's current target list. Given how long this group sustains access once inside, the more useful question isn't how they got in but how long they've already been there.

© 2026 Threat Vectr