Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecritical-infrastructure-threatstate-sponsored-disruptiongovernment-diplomatic-threat

Cyber operations and attempted sabotage targeting national power grids amid Venezuela and Poland crises

Updated 3mo agoFirst seen Jan 16, 20262 sources

Reporting described multiple state-linked cyber activities tied to geopolitical events, including a phishing campaign attributed with moderate confidence to China-nexus espionage group Mustang Panda (aka UNC6384, Twill Typhoon) that used the capture of Venezuelan President Nicolás Maduro as a lure to target US government agencies and policy organizations. Acronis researchers identified a ZIP lure (“US now deciding what’s next for Venezuela”) containing a legitimate executable side-loaded with a hidden DLL backdoor dubbed Lotuslite, though it remains unclear whether any targets were successfully compromised.

Separately, unnamed US officials cited by The New York Times claimed a “precise” US cyber operation—reportedly involving US Cyber Command—briefly disrupted electricity in Caracas and interfered with Venezuelan military radar to support the helicopter mission that captured Maduro, but public technical details of the methods used were not provided. In Europe, Poland said it repelled what it described as its most serious cyberattack on energy infrastructure in years after attackers targeted communications between distributed renewable generation (solar and wind) and electricity distribution operators, an incident officials said came close to a blackout and “everything points to” **Russian sabotage,” while withholding specific technical indicators or a formal threat-actor attribution.

Share:
Cyber operations and attempted sabotage targeting national power grids amid Venezuela and Poland crises
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 15, 20265mo ago

Acronis attributes Lotuslite campaign to Mustang Panda

Acronis assessed with moderate confidence that the Lotuslite activity was linked to the China-associated espionage group Mustang Panda, also known as UNC6384 and Twill Typhoon. The attribution was based on infrastructure and technical overlaps observed during analysis.

Mustang Panda launches Venezuela-themed phishing campaign against U.S. targets

Acronis Threat Research Unit reported that a China-linked espionage campaign used Venezuela-themed attachments to target U.S. government agencies and policy organizations. Researchers said the lure appeared to capitalize on the reported capture of Nicolás Maduro and involved a DLL-sideloading chain delivering the Lotuslite backdoor.

U.S. operation reportedly disrupts Caracas power and radar during Maduro capture

Unnamed U.S. officials told The New York Times that a purported U.S. cyber operation briefly disrupted electricity in Caracas and targeted Venezuelan military radar defenses during the mission to capture President Nicolás Maduro. The report said most residents lost power for only minutes, while some neighborhoods near the military base where Maduro was seized experienced outages lasting up to three days.

Jan 5, 20266mo ago

Researchers discover Lotuslite malware sample on VirusTotal

In early January, researchers identified a ZIP archive uploaded to VirusTotal containing a legitimate executable and a malicious DLL used to sideload the Lotuslite backdoor. The sample provided evidence of the phishing campaign and its tooling, though Acronis said it was unknown whether any victims were successfully compromised.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
VirustotalWindowsVmware Esxi
Organizations
5 linked
TencentThe RegisterAcronisVirustotalThe New York Times Company
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cyber operations and attempted sabotage targeting national power grids amid Venezuela and Poland crises | Mallory