LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing

Security experts have revealed information on a new effort that uses politically themed baits to deliver a backdoor known as LOTUSLITE to U.S. government and policy entities.

The targeted malware campaign distributes a ZIP package (“US now deciding what’s next for Venezuela.zip”) that contains a malicious DLL that is launched using DLL side-loading techniques by leveraging decoys connected to current geopolitical developments between the United States and Venezuela. Whether the campaign was successful in compromising any of the targets remains unknown.

Citing tactical and infrastructure trends, the activity has been moderately confidently linked to a Chinese state-sponsored outfit called Mustang Panda (also known as Earth Pret, HoneyMyte, and Twill Typhoon). It’s important to note that the threat actor is well-known for heavily depending on DLL side-loading read more about LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *