SloppyLemming Group Deploys Dual Malware Chains Against South Asian Governments
Mar 3, 2026 // 12:16 - Norina Velotta


The threat actor SloppyLemming (also known as Outrider Tiger or Fishing Elephant) has launched a sophisticated cyber-espionage campaign targeting government and critical infrastructure entities in Pakistan and Bangladesh.

According to a report from Arctic Wolf, the group utilized two distinct malware chains throughout late 2024 and early 2025:

Malware Chains & Tooling

  • BurrowShell Implant: Delivered via a PDF lure using a ClickOnce execution chain. This in-memory shellcode provides remote command execution and network pivoting capabilities.
  • Rust-Based RAT: Delivered through macro-laden Excel spreadsheets. The use of Rust marks an evolution from the group’s previous reliance on traditional frameworks like Cobalt Strike.
  • DLL Search Order Hijacking: Both chains use legitimate, signed Microsoft executables to sideload malicious DLLs, allowing the malware to run within trusted processes to evade detection.

Targets & Infrastructure

  • Primary Targets: Pakistani government agencies, law enforcement, telecommunications, energy, and the country’s sole nuclear power facility.
  • Regional Reach: In Bangladesh, the focus has been on energy utilities and military organizations.
  • Cloud Exploitation: The group heavily abuses Cloudflare Workers to host command-and-control (C2) infrastructure and credential harvesting pages.
  • Domain Impersonation: Over 112 unique domains were identified, many specifically crafted to impersonate official government portals to increase the success of phishing attempts.

SloppyLemming is widely believed to be an India-nexus threat actor, with operations aligning closely with Indian government interests since at least 2021.

#against  #asian  #chains  #deploys  #dual  #governments  #group  #malware  #news  #sloppylemming  #south   —   News