---
title: "ITG27, a China-aligned state-sponsored espionage group, has intensified attacks on India’s energy sector as of mid-2026; Havencode backdoor discovered"
sdDatePublished: "2026-08-21T05:11:00Z"
source: "https://www.ibm.com/think/x-force/trapping-a-mustang-panda"
topics:
  - name: "cyber crime"
    identifier: "medtop:20000086"
  - name: "espionage and intelligence"
    identifier: "medtop:20000605"
  - name: "international relations"
    identifier: "medtop:20000638"
  - name: "energy industry"
    identifier: "medtop:20000261"
locations:
  - "Arunachal Pradesh"
  - "Taiwan"
  - "China"
  - "India"
  - "Nepal"
  - "Bangladesh"
---


ITG27, a China-aligned state-sponsored espionage group, has intensified attacks on India’s energy sector as of mid-2026; Havencode backdoor discovered

Trapping a Mustang Panda | IBM

Get hands-on experience with IBM tech Join one of the largest technical IBM community gatherings! ITG27’s attacks on India’s energy sector—uncovered by IBM X-Force & Deception.Pro—reveal new tactics & vulnerabilities. Read more to understand the threat & implement robust defenses. As of mid-2026, IBM X-Force continues to monitor cyber campaigns conducted by ITG27, a China-aligned state-sponsored espionage group whose victims align with China’s regional strategic interests. In collaboration with Deception.Pro, X-Force captured live ITG27 activity in simulated enterprise environments, including the deployment of a previously undiscovered VNC-capable backdoor named Havencode. The observed activity extends a campaign previously reported by Acronis, where ITG27 targeted India’s energy sector and government organizations. This campaign relied on the use of Claimloader malware, lure documents, and the Toneshell backdoor. The campaign coincides with intensifying China-India competition over regional hydropower and India’s expanding strategic relationships with partners such as Taiwan. X-Force analysts captured live ITG27 operator activity in fake enterprise environments designed to resemble an operational technology company specializing in electric grids and a state-level government agency. Across both incidents, operators conducted reconnaissance, harvested credentials and deployed malware. In the first incident, ITG27 deployed a previously undiscovered VNC-capable backdoor that X-Force named Havencode. In the second, operators collected fake documents from infected systems and exfiltrated them to an attacker-controlled SFTP server. Our report explores the evolving geopolitical backdrop along with potential ties to cyber operations conducted by China-aligned threat activity while highlighting ITG27’s updated Tools, Tactics, and Procedures (TTPs) and concluding with recommendations organizations may employ in their cyber defense efforts. ITG27, formerly Hive0154, is a state sponsored espionage group aligned to the strategic interests of China. Since at least 2024, ITG27 has engaged in cyberattacks targeting public and private organizations, including think tanks, policy groups, government agencies and individuals. X-Force assesses ITG27 conducts cyber operations primarily in alignment with China’s regional interests but may extend its targeting of Western entities perceived to threaten China’s economic or military objectives. ITG27 activity overlaps with threat actors publicly reported as Mustang Panda, Stately Taurus, UNK_SteadySplit, Camaro Dragon, Twill Typhoon, Polaris, and Earth Preta. ITG27 employs a large malware arsenal to conduct espionage. Their arsenal includes, actively developed custom malware loaders, backdoors, USB worms and extending legitimate commercial infrastructure within their campaigns. Associated malware families such as Toneshell, Pubload and Claimloader undergo frequent updates that enhance ITG27’s adaptability within their target environments. As an example, Toneshell is tracked at its tenth iteration featuring updated command and control (C2) protocols. In May 2026, X-Force uncovered an email with the subject ‘China BG’ delivered to recipients within the Indian government. The email includes a PDF attachment titled, “Hydropower Cooperation Project Study.pdf” imitating Nepal’s Ministry of Foreign Affairs (MoFA). The lure PDF highlights two key offices, the Office of the Minister of External Affairs and the Office of the Minister of Power (sic) within India’s Government. Both offices are responsible for India’s diplomacy and energy interests at the highest levels. The lure’s hydropower theme aligns with India’s longstanding concerns about transboundary river and dam projects. Many major South Asian rivers originate in the Himalayas or Tibetan Plateau and cross-national borders, making upstream infrastructure relevant to water management, energy security, border politics and regional competition. This context may explain why an attacker targeting Indian government and energy organizations would use hydropower cooperation as a credible lure, but the lure alone does not establish the operators’ specific intelligence requirements. The most critical issue centers on the Brahmaputra River system, known in China as the Yarlung Zangbo or Yarlung Tsangpo. Originating in Tibet, the river flows through China before entering India via Arunachal Pradesh and continuing into Bangladesh. China’s control over the upstream section has heightened Indian concerns over large-scale Chinese hydropower projects, including the ongoing construction of Motuo (aka Medong) Hydropower Station on the Yarlung Tsangpo. This project is expected to become one of the world’s largest hydroelectric installations when completed. Indian policymakers and analysts are particularly concerned that such projects could alter water flows, enhance China’s strategic leverage, as well as generate political, economic and military implications for downstream countries. In response, India has accelerated several dam and hydropower projects in Arunachal Pradesh and adjacent regions. These projects serve not only developmental and energy objectives but also strategic purposes, reinforcing India’s presence in contested border regions and strengthening its capacity to manage potential upstream disruptions. Amid continuing uncertainty over long-term water-sharing arrangements and China’s willingness to accommodate Indian concerns regarding downstream water rights, India is also planning the Siang River dam project, partly intended to mitigate the risks associated with sudden water releases or other hydrological impacts originating from upstream Chinese infrastructure. Against this geopolitical backdrop, Indian government information about current and planned hydropower projects could be valuable to a state-aligned intelligence service. Information about critical infrastructure may also provide strategic or operational insight. However, the observed campaign evidence supports an espionage assessment more directly than any conclusion about preparations for disruptive operations. As previously reported by Acronis, within the PDF is a malicious Dropbox link to download an archive containing a loader identified as a Claimloader (ebd533de7ca16daa70093b0b1084fb6136b6ba091d6ee0e4199762581e1b2e5a) variant, leading to ITG27’s hallmark Toneshell backdoor (b7aa6cda2d08f5f2d9b422446a2abfbf6a84f35285b139af6a24c020076bb0e0). Further analysis revealed connections to other adjacent campaigns including two additional malicious archives titled “Letter to his Excellency the President.zip” (db4176b0c83065f4f4820aded7f7170d28268a253b28ed09e8067f39ab554d78), and “TP.zip” (39ba7a4ae768b175e7168066a3df2b4df2ca64a91d12f6e1400efee0ed9fd568). X-Force identified multiple related lure archives associated with this campaign, including “Hydropower Cooperation Project Proposal.zip”, “Letter to His Excellency the President.zip” and “TP.zip”. The samples were submitted from India and share highly consistent execution chains, malware components, persistence mechanisms and command-and-control infrastructure. Together, these similarities support the assessment that the samples belong to the same ITG27 campaign cluster. The “Hydropower Cooperation Project Proposal.zip” archive contains a legitimate executable, “Project Proposal.exe”, which side-loads a malicious DLL named “SolidPDFCreator.dll”. The DLL functions as a malware loader that X-Force tracks as a new variant of Claimloader, a malware family consistently associated with ITG27 intrusion activity. The second sample, “Letter to His Excellency the President.zip”, follows the same infection chain. The archive contains a legitimate executable named “Letter to His Excellency the President.exe”, which side-loads the malicious DLL loader, “SolidPDFCreator.dll”. The third sample, archive “TP.zip”, contains a legitimate executable named “Talking Points(PM) 14 00hrs(Final version) - PW.exe”, which side-loads the malicious DLL loader, “SolidPDFCreator.dll”. Behavioral analysis showed identical installation logic and persistence behavior between all samples. Acronis previously reported overlapping activity involving the same campaign cluster but categorized portions of the toolchain differently. X-Force identifies the sideloaded DLL component as Claimloader, based on its consistent role as a loader-stage implant. The malware copies the sideloading pair to a new installation directory (commonly under C:\ProgramData), establishes persistence, recovers embedded shellcode and executes Toneshell payload using a Windows enumeration callback. The loaders subsequently execute embedded shellcode using the EnumSystemLocalesA API as a callback mechanism. In all infection chains, the exact same Toneshell payload is deployed, identified by the SHA256 hash b7aa6cda2d08f5f2d9b422446a2abfbf6a84f35285b139af6a24c020076bb0e0. The payload consists of raw 32-bit shellcode and executes entirely in memory beginning at offset 0xD0. X-Force tracks this variant as Toneshell v10, which reflects continued evolution of the malware family previously associated with ITG27 operations. Earlier variants relied on custom socket-based communications, while version 10 transitions to secure WebSocket communications using WinHTTP over TLS. In all three samples, “SolidPDFCreator.dll” installs itself into: C:\ProgramData\IDM\logs\ The malware copies: C:\ProgramData\IDM\logs\MediumInstStart.exe C:\ProgramData\IDM\logs\SolidPDFCreator.dll Persistence is established through the current user Run registry key: MediumNetMonIt = C:\ProgramData\IDM\logs\MediumInstStart.exe The malware establishes command-and-control using the following parameters: Associated infrastructure observed serving Toneshell command-and-control traffic includes: Toneshell v10 preserves the existing Toneshell command model for reverse-shell access and file upload operations. The malware supports interactive shell access, session management and staged file transfer functionality through the following commands: In addition to the shellcode-based Toneshell payloads delivered through Claimloader, X-Force identified three PE32 DLL samples belonging to the same Toneshell v10 lineage. These samples differ from the shellcode payloads in packaging and masquerading strategy. Their underlying implementation, however, is the same: all three reuse the WinHTTP-based WebSocket communications model, command dispatcher logic, proxy handling and reverse-shell functionality observed in the shellcode payloads deployed during the monitored intrusions. The identified DLL variants are: The first two PE32 DLL variants reuse the “SolidPDFCreator.dll” name, while the third uses a “libcef.dll” masquerade. Notably, fdcvgbb[.]com resolved to the same IP address as couldinstallup[.]com (194[.]5[.]97[.]169), which further links the PE32 DLL variants to the same Toneshell v10 infrastructure cluster. All three samples implement native WinHTTP WebSocket communications over TLS and support the same command model as the raw shellcode Toneshell payloads previously discussed. The malware uses the WinHTTP WebSocket API set, including: The samples also contain proxy fallback behavior using: X-Force observed multiple constants and implementation artifacts consistent with the broader Toneshell malware lineage, including 13131313, 11313, 0xBD828 and 0x4373A. The PE32 DLL variants also reuse the same PRNG-derived XOR key generation pattern, previously identified in shellcode-based Toneshell samples. All three PE32 DLL variants implement the same command opcode model as the shellcode payloads, supporting keepalive handling, C2-to-victim file upload and drop functionality and redirected reverse-shell channel control. A notable characteristic across the Toneshell DLL samples is the presence of repeated UTF-16LE junk strings referencing characters and themes