Mysterious Elephant is a South Asia-focused cyber-espionage threat actor tracked since at least 2023 and widely assessed as part of the India-aligned intrusion ecosystem. The group is also referred to as APT-K-47 and has been associated in public reporting with aliases including TAG-179 and APT-C-08, although some of those labels also overlap with reporting on Bitter and should be treated cautiously. Mysterious Elephant has shown tactical and tooling commonalities with other suspected India-nexus actors, especially Confucius, SideWinder, Origami Elephant, and Bitter, suggesting code sharing, shared resourcing, or coordinated tasking across parts of that ecosystem. The actor primarily targets government, diplomatic, foreign affairs, military, and defense organizations across the Asia-Pacific region, with a strong concentration on Pakistan and Bangladesh and additional targeting reported in Afghanistan, Nepal, Sri Lanka, and India. Victimology and lure themes indicate a strong interest in South Asian diplomacy, regional security affairs, and Pakistani state institutions. Reporting has also linked overlapping infrastructure and tradecraft to intrusions affecting Pakistani law-enforcement organizations. Mysterious Elephant relies heavily on spear-phishing and malicious document delivery for initial access. Observed infection chains have used diplomatic and government-themed lures, remote template injection, exploit kits, and exploitation of CVE-2017-11882 and CVE-2023-38831. The group commonly uses decoy documents aligned to current geopolitical or administrative themes to induce execution. PowerShell has featured prominently in more recent campaigns for staging, payload retrieval, execution, and persistence. Its malware arsenal includes both custom tooling and modified open-source malware. Publicly associated families and components include BabShell, MemLoader, Remcos RAT, VRat derived from vxRat, Asyncshell, ORPCBackdoor, walkershell, MSMQSPY, LastopenSpy, and exfiltration modules focused on browser and messaging data theft. BabShell is a C++ reverse shell used for command execution and staging. MemLoader variants have been used for in-memory loading of follow-on payloads, anti-sandbox checks, hidden-desktop execution, and reflective loading. Some campaigns deployed Remcos RAT in memory, while another MemLoader branch embedded a vxRat-based backdoor referred to as VRat. Earlier activity also used tooling linked by other researchers to broader Indian threat-actor code-sharing ecosystems. A notable operational objective is theft of sensitive communications and documents, including artifacts associated with WhatsApp Desktop and Chrome browser data that may expose messaging-related content, tokens, cookies, and transferred files. This emphasis on diplomatic and communications data is consistent with intelligence collection against foreign affairs and government targets. Tradecraft attributed to Mysterious Elephant has evolved over time. Earlier operations resembled Confucius-style activity and reused or maintained malware code associated with other regional actors. More recent campaigns show greater use of custom loaders, in-memory execution, anti-analysis logic, persistence via scheduled tasks or autostart mechanisms, and modular exfiltration workflows. The group’s operations indicate sustained espionage intent rather than disruptive or financially motivated objectives. Overall, Mysterious Elephant is best characterized as a persistent cyber-espionage actor focused on South Asian strategic intelligence collection, especially against Pakistani and neighboring government-linked targets, using phishing-led intrusion chains, shared regional tooling, and increasingly mature custom malware for stealthy access and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
India-nexus intrusion set linked here through infrastructure and tactical overlaps with the Remcos RAT activity targeting Pakistani law enforcement organizations.
Named as overlapping with TAG-179 in infrastructure, tooling, and TTPs in India-nexus espionage activity.
India-nexus cyber-espionage group tracked by Kaspersky; primarily targets diplomatic, military, and defense institutions in Pakistan and Bangladesh; assessed as distinct from Sloppy Lemming.
Targeting government and foreign affairs sectors in South Asia using exploit kits, phishing, and a chain of custom and open-source malware for espionage and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.