Same packet, different magic: Hits India's banking sector and Korea geopolitics

Reported 22 Apr 2026 by otx · Severity: medium

A new variant of the LOTUSLITE backdoor, version 1.1, has been identified targeting India's banking sector and South Korean diplomatic circles. The backdoor is delivered via DLL sideloading using legitimate Microsoft-signed executables and initially through CHM files containing m