Skip to main content
Mallory
🇵🇰 PK6 malware families

SloppyLemming

Also known asSloppyLemming

SloppyLemming is an India-nexus cyber-espionage threat actor, also tracked as Outrider Tiger and Fishing Elephant. Reporting in the provided content attributes campaigns from at least 2021 or 2022 through January 2026 to this cluster, with targeting focused on government, law enforcement, defense, energy, telecommunications, technology, and other critical infrastructure entities in Pakistan and Bangladesh, and additional historical targeting noted in Sri Lanka, Nepal, Indonesia, China, and broader South and East Asia. Specific victim sectors and entities mentioned include Pakistani nuclear regulatory, defense logistics, navy, telecom, and government organizations, as well as Bangladeshi energy utilities and financial institutions. The actor is described as conducting cyber-espionage aligned with Indian state intelligence collection requirements or Indian government interests. Arctic Wolf assessed the group as moderately capable. Observed tradecraft includes spear-phishing and social engineering using PDF lures and macro-enabled Excel documents; trust-based execution chains involving ClickOnce, LNK, and ISO files; DLL side-loading and search-order hijacking; use of legitimate Microsoft binaries; persistence via Run keys; screenshot capture; keylogging; remote shell execution; file manipulation; network tunneling via SOCKS proxy; port scanning; and network enumeration. The content also notes use of Cloudflare Workers infrastructure, including government-themed typosquatting domains for payload delivery and command-and-control, and prior use of Havoc, Cobalt Strike, Ares RAT, WarHawk, and a custom NekroWire RAT. Malware and tooling directly mentioned in the content include BurrowShell, a full-featured backdoor with file manipulation, screenshot capture, remote shell execution, and network tunneling capabilities, and a Rust-based RAT/keylogger with reconnaissance features. The actor is also described as producing multiple malware variants in AI-assisted and non-mainstream programming languages, and as shifting toward Rust-based tooling in more recent campaigns.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • PK
MITRE ATT&CK

Tradecraft

34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics52 techniquesĂ—N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.001Ă—2
Domains
T1587
Develop Capabilities
T1587.001
Malware
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001Ă—4
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
3 techniques
T1059
Command and Scripting Interpreter
T1059.005Ă—3
Visual Basic
T1204Ă—3
User Execution
T1204.002
Malicious File
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
5 techniques
T1027
Obfuscated Files or Information
T1027.002
Software Packing
T1036
Masquerading
T1036.005
Match Legitimate Resource Name or Location
T1140Ă—2
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.007Ă—2
Msiexec
T1574
Hijack Execution Flow
T1574.001
DLL
TA0006
Credential Access
1 technique
T1056
Input Capture
T1056.001Ă—3
Keylogging
TA0007
Discovery
4 techniques
T1046Ă—3
Network Service Discovery
T1057
Process Discovery
T1082
System Information Discovery
T1083
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
3 techniques
T1056
Input Capture
T1056.001Ă—3
Keylogging
T1113Ă—3
Screen Capture
T1560
Archive Collected Data
TA0011
Command and Control
7 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.001
Internal Proxy
T1090.003
Multi-hop Proxy
T1102
Web Service
T1102.002
Bidirectional Communication
T1105
Ingress Tool Transfer
T1571
Non-Standard Port
T1572
Protocol Tunneling
T1573
Encrypted Channel
T1573.001
Symmetric Cryptography
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
1 technique
T1565
Data Manipulation
T1565.001
Stored Data Manipulation
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping34

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

SloppyLemming | Mallory