logo

SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets

ID: 2370efa3-5053-51f7-be50-a1cb57fc02c5

STIX ID: report--2370efa3-5053-51f7-be50-a1cb57fc02c5

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

- SloppyLemming conducted a year-long espionage campaign (Jan 2025–Jan 2026) targeting government, defense, nuclear oversight, utilities, and financial organizations in Pakistan and Bangladesh using two spear-phishing paths: a PDF lure that led to a ClickOnce chain deploying an in-memory backdoor (BurrowShell) via DLL search-order hijacking, and macro-enabled Excel spreadsheets that delivered a Rust-based RAT with keylogging; researchers observed large-scale supporting infrastructure (112 Cloudflare Workers domains impersonating government entities) and provided IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.