Back Scworld SloppyLemming targets Pakistan and Bangladesh with new malware | brief
As reported by The Hacker News, the threat activity cluster known as SloppyLemming has been linked to a new wave of cyberattacks targeting government entities and critical infrastructure operators in Pakistan and Bangladesh. These attacks, which occurred between January 2025 and January 2026, highlight the evolving tactics of sophisticated threat actors, according to Arctic Wolf.
The SloppyLemming group employed two distinct attack chains to deploy malware. One chain utilized spear-phishing emails containing PDF lures and macro-enabled Excel documents. These led victims to ClickOnce application manifests that deployed a malicious loader, which in turn executed BurrowShell, a full-featured backdoor capable of file manipulation, remote shell execution, and network tunneling. The second attack chain used Excel documents with malicious macros to deliver a Rust-based keylogger, also incorporating port scanning and network enumeration features. This evolution includes the use of the Rust programming language, a departure from reliance on traditional compiled languages and frameworks like Cobalt Strike and Havoc.
The targeting of critical sectors like energy, telecommunications, and defense in South Asia suggests intelligence gathering aligned with regional strategic competition. The observed increase in Cloudflare Workers domains used for command-and-control infrastructure, alongside the dual payload strategy, indicates a flexible and adaptive threat actor.
Source: The Hacker News
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
