The threat actor SloppyLemming (also known as Outrider Tiger or Fishing Elephant) has launched a sophisticated cyber-espionage campaign targeting government and critical infrastructure entities in Pakistan and Bangladesh.
According to a report from Arctic Wolf, the group utilized two distinct malware chains throughout late 2024 and early 2025:
Malware Chains & Tooling
- BurrowShell Implant: Delivered via a PDF lure using a ClickOnce execution chain. This in-memory shellcode provides remote command execution and network pivoting capabilities.
- Rust-Based RAT: Delivered through macro-laden Excel spreadsheets. The use of Rust marks an evolution from the group’s previous reliance on traditional frameworks like Cobalt Strike.
- DLL Search Order Hijacking: Both chains use legitimate, signed Microsoft executables to sideload malicious DLLs, allowing the malware to run within trusted processes to evade detection.
Targets & Infrastructure
- Primary Targets: Pakistani government agencies, law enforcement, telecommunications, energy, and the country’s sole nuclear power facility.
- Regional Reach: In Bangladesh, the focus has been on energy utilities and military organizations.
- Cloud Exploitation: The group heavily abuses Cloudflare Workers to host command-and-control (C2) infrastructure and credential harvesting pages.
- Domain Impersonation: Over 112 unique domains were identified, many specifically crafted to impersonate official government portals to increase the success of phishing attempts.
SloppyLemming is widely believed to be an India-nexus threat actor, with operations aligning closely with Indian government interests since at least 2021.