The break is that ordinary SaaS traffic is now the control plane. Mustang Panda is hiding commands and stolen data inside Zoho WorkDrive, so network monitoring sees legitimate cloud use instead of a malware beacon.
Acronis says the group used that channel in active compromises against Indian government and hydropower targets, including systems used by senior administrative staff. The campaign also introduced new tools, including SHARDLOADER, MINIRECON, and ZOHOMURK, with ZOHOMURK using a WorkDrive account as a dead drop and reading commands from one folder before writing output to another.
That makes cloud-account abuse the thing to watch, not just suspicious external callbacks. If a trusted storage service carries the C2 and exfiltration, the attacker can stay blended into normal admin traffic for longer.