SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets
ID: 2370efa3-5053-51f7-be50-a1cb57fc02c5
STIX ID: report--2370efa3-5053-51f7-be50-a1cb57fc02c5
Feed Name: cybersecurityNews.com
- SloppyLemming conducted a year-long espionage campaign (Jan 2025–Jan 2026) targeting government, defense, nuclear oversight, utilities, and financial organizations in Pakistan and Bangladesh using two spear-phishing paths: a PDF lure that led to a ClickOnce chain deploying an in-memory backdoor (BurrowShell) via DLL search-order hijacking, and macro-enabled Excel spreadsheets that delivered a Rust-based RAT with keylogging; researchers observed large-scale supporting infrastructure (112 Cloudflare Workers domains impersonating government entities) and provided IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
