216.73.216.6

Targeted espionage leveraging geopolitical themes

· Published 15/01/2026 12:03 · Modified 19/01/2026 09:30

Export JSON

Essential information

Published
15/01/2026 12:03
Modified
19/01/2026 09:30
Tags
2026-01-15 backdoor dll sideloading espionage geopolitical lures lotuslite u.s. government venezuela
Related entities
4 observables, 1 intrusion sets (apt), 5 techniques (mitre), 1 malware, 4 others

Description

A targeted malware campaign against entities has been observed, utilizing a politically themed ZIP archive containing a loader executable and a malicious DLL. The DLL functions as a named , communicating with a hard-coded command-and-control server. The campaign demonstrates minimal technical sophistication but shows deliberate victim selection and use of . Attribution analysis suggests moderate-confidence overlap with Mustang Panda tradecraft, including delivery style, loader-DLL separation, and infrastructure usage. The supports basic remote tasking and data exfiltration, indicating an -focused capability. This activity reflects a trend of targeted spear phishing using geopolitical themes and reliable execution techniques like .

External references