SYMBOLCOMMON_NAMEaka. SYNONYMS
win.zohomurk (Back to overview)

ZOHOMURK

Actor(s): MUSTANG PANDA


According to Acronis, ZOHOMURK is a newly identified DLL implant written in C/C++ that abuses the legitimate Zoho WorkDrive cloud storage service for command-and-control, data exfiltration and remote task execution. It is sideloaded via a signed Citrix Receiver binary dropped by its SHARDLOADER parent, with a single export function serving as the implant's entry point and timing-based anti-debug checks guarding key steps such as registry writes and initial beaconing. Capabilities include an interactive shell via a pipe, file upload/download handled through a small opcode-driven dispatcher, victim registration by creating folders on the operator's WorkDrive account, OAuth-based authentication with hardcoded credentials, a heartbeat/re-registration thread, and Run-key persistence established only after passing environment and timing checks

References
2026-06-28AcronisSantiago Pontiroli, Subhajeet Singha
Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON
MINIRECON ZOHOMURK

There is no Yara-Signature yet.