Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Exploring the closed nuclear fuel cycle: From recycling to fuel

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » LOTUSLITE backdoor targets US policy agencies using Venezuela-themed spear phishing
Identity

LOTUSLITE backdoor targets US policy agencies using Venezuela-themed spear phishing

userBy userJanuary 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 16, 2026Ravi LakshmananMalware/Cyber ​​Espionage

Security experts have revealed details of a new campaign targeting U.S. government and policy actors using politically-themed decoys to deliver a backdoor known as LOTUSLITE.

The targeted malware campaign utilizes decoys related to recent geopolitical developments between the United States and Venezuela to distribute a ZIP archive (“US deciding what’s next for Venezuela. zip”) containing a malicious DLL that is launched using DLL sideloading techniques. It is unclear whether this campaign was successful in compromising any of its targets.

This activity is believed with some confidence to be the work of a Chinese state-sponsored group known as Mustang Panda (also known as Earth Pret, HoneyMyte, and Twill Typhoon), citing tactical and infrastructure patterns. It is worth noting that this threat actor is known to rely extensively on DLL sideloading to launch backdoors such as TONESHELL.

cyber security

“This campaign reflects a continuing trend of targeted spear phishing using geopolitical lures, favoring reliable execution techniques such as DLL sideloading over exploit-based initial access,” Acronis researchers Ilya Davchev and Subhajit Sinha said in an analysis.

The backdoor used in this attack (‘kugou.dll’), LOTUSLITE, is a custom-built C++ implant that uses the Windows WinHTTP API to communicate with a hard-coded command and control (C2) server, enabling beacon activity, remote tasks using ‘cmd.exe’, and data exfiltration. The complete list of supported commands is:

0x0A, Start remote CMD shell 0x0B, Exit remote shell 0x01, Send command via remote shell 0x06, Reset beacon state 0x03, Enumerate files in folder 0x0D, Create empty file 0x0E, Append data to file 0x0F, Get beacon status

LOTUSLITE can also be made persistent by modifying the Windows registry so that LOTUSLITE runs automatically every time a user logs into the system.

Acronis said the backdoor “mimics Claimloader’s fraudulent behavior by embedding provocative messages.” Claimloader is the name assigned to a DLL that is launched using DLL sideloading and is used to deploy PUBLOAD, another Mustang Panda tool. This malware was first documented by IBM X-Force in June 2025 in connection with a cyberespionage campaign targeting the Tibetan community.

“This campaign shows how effective simple, well-tested techniques can be when combined with targeted delivery and relevant geopolitical lures,” the Singaporean cybersecurity firm concluded. “Although the LOTUSLITE backdoor lacks sophisticated evasion capabilities, its use of DLL sideloading, reliable execution flows, and basic command and control functionality reflects a focus on operational reliability over sophistication.”

cyber security

The revelations came as The New York Times published details of a cyberattack allegedly carried out by the United States to cut off power to most residents of the capital, Caracas, for several minutes ahead of a military operation to capture Venezuelan President Nicolas Maduro on January 3, 2026. mission

“Turning off power and jamming Caracas’ radar allowed a U.S. military helicopter to enter the country undetected on a mission to capture Venezuelan President Nicolás Maduro, who was taken to the United States on drug charges,” the Times reported.

“The attack left most of Caracas without power for several minutes, but some areas near the military base where Mr. Maduro was held remained without power for up to 36 hours.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWorld-class rare earth magnet recycling facility begins operations in the UK
Next Article Your digital footprint can end right at your doorstep
user
  • Website

Related Posts

Unmasking new TOAD attacks hidden in legitimate infrastructure

January 28, 2026

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

January 28, 2026

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Exploring the closed nuclear fuel cycle: From recycling to fuel

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Everything you need to know about the viral personal AI assistant Clawdbot (now Moltbot)

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.