Back Industrialcyber.Co SloppyLemming espionage surge hitting defense, telecom, energy and finance in Pakistan ...
New data from Arctic Wolf Labs shows that a threat actor known as SloppyLemming, also called Outrider Tiger and Fishing Elephant, conducted an extensive cyber espionage campaign from January 2025 to January this year. The campaign focused on government entities and critical infrastructure operators in Pakistan and Bangladesh, expanding the publicly documented scope of this group’s activities across South Asia.
“Arctic Wolf assesses with moderate confidence that this activity is attributable to SloppyLemming, based on continued exploitation of Cloudflare Workers infrastructure with government-themed typo-squatting patterns, deployment of the Havoc C2 framework previously linked to this actor, DLL sideloading techniques consistent with documented tradecraft, and victimology focused on South Asian government and critical infrastructure entities matching established targeting priorities,” according to a Monday blog post . “In particular, the targeting of Pakistani nuclear regulatory bodies, defense logistics organizations, and telecommunications infrastructure – alongside Bangladeshi energy utilities and financial institutions – aligns with intelligence collection priorities consistent with regional strategic competition in South Asia.”
Researchers also assess that Sri Lanka has emerged as a secondary target, with activity directed at defense-related entities.
Arctic Wolf reports that the latest activity represents a direct continuation of operations previously attributed to SloppyLemming and documented by Cloudflare’s CloudForce One in September 2024, though the group has since expanded its tooling and infrastructure. The threat actor relies on multi-stage execution chains that use ClickOnce application manifests and macro-enabled Office documents to deliver payloads through DLL order hijacking, abusing legitimate Microsoft binaries such as NGenTask[dot]exe and phoneactivate[dot]exe to evade detection.
Researchers identified two custom implants deployed in the campaign. The first, known as BurrowShell, is an in-memory x64 shellcode backdoor that enables C2 (command-and-control) communication and supports SOCKS proxy tunneling for lateral movement . BurrowShell executes fifteen distinct commands, allowing operators to manipulate files, capture screenshots, run shell commands, and pivot across compromised networks. The second implant is a Rust-based keylogger with expanded information-stealing capabilities, including remote command execution, file operations, and network reconnaissance.
The campaign uses 112 unique Cloudflare Workers domains that impersonate Pakistani and Bangladeshi government entities to facilitate both payload delivery and command-and-control communications. Arctic Wolf researchers also identified operational security failures, including multiple C2 domains configured as open directories that exposed malware components and artifacts linked to the Havoc command-and-control framework, providing rare visibility into the group’s infrastructure.
Targeted sectors include government agencies, defense organizations such as the Pakistan Navy and National Logistics Corporation, energy utilities including DESCO and PGCB, telecommunications providers such as SCO and PTCL, and nuclear regulatory bodies including PNRA across Pakistan and Bangladesh.
The campaign Arctic Wolf observed employs two primary attack vectors, both initiated through spear-phishing . The first vector uses PDF documents containing embedded malicious URLs that redirect victims to ClickOnce application manifest files, which orchestrate the download and execution of a multi-component payload chain. The second vector uses macro-laden Excel spreadsheets that directly download and execute malicious binaries.
Both attack chains ultimately achieve code execution through DLL order hijacking, whereby legitimate, digitally signed Microsoft executables are placed alongside malicious DLLs that the executables automatically load during initialization. This technique allows the threat actor to execute malicious code within the context of trusted processes, potentially bypassing security controls that rely on process reputation.
In conclusion, Arctic Wolf assesses with moderate confidence that the investigation documents an ongoing cyber espionage campaign carried out by the suspected India-aligned threat actor SloppyLemming. The campaign represents a continuation and evolution of activity documented by Cloudflare’s CloudForce One in September 2024, with the threat actor expanding its infrastructure and tooling while maintaining consistent targeting patterns focused on Pakistani and Bangladeshi government and critical infrastructure entities.
“From a geopolitical perspective, the targeting of Pakistani nuclear regulatory bodies, defense logistics organizations, and telecommunications infrastructure – alongside Bangladeshi energy utilities and financial institutions – aligns with intelligence collection priorities consistent with regional strategic competition in South Asia,” it added. “Organizations within these sectors should consider themselves potential targets and implement appropriate defensive measures.”
The Arctic Wolf disclosure comes amid widening Middle East tensions that have spilled over into the cyber and critical infrastructure domains. After a coordinated U.S.-Israeli military and cyber campaign against Iran, Tehran responded with a broad counteroffensive that has included near-total internet blackouts, pro-Iran hacktivist mobilization, and threats against Western and Gulf critical infrastructure operators.
Analysts noted an active digital battlefield in which pro-Iran groups are engaging in ransomware claims against energy firms and regional critical infrastructure sectors, and where Iranian state and proxy operations are increasingly seen as capable of targeting energy, telecom, water, and other essential services across the Gulf as part of a multi-domain response to the ongoing conflict.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
