Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » LOTUSLITE backdoor targets US policy agencies using Venezuela-themed spear phishing
Celebrities

LOTUSLITE backdoor targets US policy agencies using Venezuela-themed spear phishing

By January 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 16, 2026Ravi LakshmananMalware/Cyber ​​Espionage

Security experts have revealed details of a new campaign targeting U.S. government and policy actors using politically-themed decoys to deliver a backdoor known as LOTUSLITE.

The targeted malware campaign utilizes decoys related to recent geopolitical developments between the United States and Venezuela to distribute a ZIP archive (“US deciding what’s next for Venezuela. zip”) containing a malicious DLL that is launched using DLL sideloading techniques. It is unclear whether this campaign was successful in compromising any of its targets.

This activity is believed with some confidence to be the work of a Chinese state-sponsored group known as Mustang Panda (also known as Earth Pret, HoneyMyte, and Twill Typhoon), citing tactical and infrastructure patterns. It is worth noting that this threat actor is known to rely extensively on DLL sideloading to launch backdoors such as TONESHELL.

cyber security

“This campaign reflects a continuing trend of targeted spear phishing using geopolitical lures, favoring reliable execution techniques such as DLL sideloading over exploit-based initial access,” Acronis researchers Ilya Davchev and Subhajit Sinha said in an analysis.

The backdoor used in this attack (‘kugou.dll’), LOTUSLITE, is a custom-built C++ implant that uses the Windows WinHTTP API to communicate with a hard-coded command and control (C2) server, enabling beacon activity, remote tasks using ‘cmd.exe’, and data exfiltration. The complete list of supported commands is:

0x0A, Start remote CMD shell 0x0B, Exit remote shell 0x01, Send command via remote shell 0x06, Reset beacon state 0x03, Enumerate files in folder 0x0D, Create empty file 0x0E, Append data to file 0x0F, Get beacon status

LOTUSLITE can also be made persistent by modifying the Windows registry so that LOTUSLITE runs automatically every time a user logs into the system.

Acronis said the backdoor “mimics Claimloader’s fraudulent behavior by embedding provocative messages.” Claimloader is the name assigned to a DLL that is launched using DLL sideloading and is used to deploy PUBLOAD, another Mustang Panda tool. This malware was first documented by IBM X-Force in June 2025 in connection with a cyberespionage campaign targeting the Tibetan community.

“This campaign shows how effective simple, well-tested techniques can be when combined with targeted delivery and relevant geopolitical lures,” the Singaporean cybersecurity firm concluded. “Although the LOTUSLITE backdoor lacks sophisticated evasion capabilities, its use of DLL sideloading, reliable execution flows, and basic command and control functionality reflects a focus on operational reliability over sophistication.”

cyber security

The revelations came as The New York Times published details of a cyberattack allegedly carried out by the United States to cut off power to most residents of the capital, Caracas, for several minutes ahead of a military operation to capture Venezuelan President Nicolas Maduro on January 3, 2026. mission

“Turning off power and jamming Caracas’ radar allowed a U.S. military helicopter to enter the country undetected on a mission to capture Venezuelan President Nicolás Maduro, who was taken to the United States on drug charges,” the Times reported.

“The attack left most of Caracas without power for several minutes, but some areas near the military base where Mr. Maduro was held remained without power for up to 36 hours.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWorld-class rare earth magnet recycling facility begins operations in the UK
Next Article Your digital footprint can end right at your doorstep

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

Swimming Pole, Billboard’s Emerging Dance Artist of the Month

Trending Posts

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Swimming Pole, Billboard’s Emerging Dance Artist of the Month

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.