China-linked threat actor Mustang Panda has been running two concurrent espionage campaigns targeting Indian government entities and the hydropower sector. The campaigns deploy new malware implants — SHARDLOADER, MINIRECON, and ZOHOMURK — with ZOHOMURK abusing Zoho WorkDrive as a command-and-control channel to blend malicious traffic with legitimate cloud activity. Attack chains use hydropower- and government-themed lure documents delivered via compressed archives, leveraging DLL side-loading. Attribution is high-confidence based on code overlaps with prior Mustang Panda tooling. CISOs are advised to monitor cloud service traffic for anomalies, hunt for DLL side-loading behavior, and model threats around geopolitical and infrastructure-themed lures.