SloppyLemming Espionage Campaign Targets Pakistan, Bangladesh with BurrowShell Backdoor and Rust RAT
ID: 18300b81-840c-5452-b211-546aa9ec5977
STIX ID: report--18300b81-840c-5452-b211-546aa9ec5977
Feed Name: GBHackers
SloppyLemming (aka Outrider Tiger/Fishing Elephant) conducted a year-long espionage campaign against Pakistani and Bangladeshi government and critical infrastructure using spear‑phishing to deliver a BurrowShell backdoor and a Rust-based keylogger/RAT via DLL sideloading and ClickOnce manifests; the group scaled Cloudflare Workers for payload delivery and C2, leaked staged malware through misconfigured Workers, and utilized both custom implants and frameworks like Havoc, prompting specific detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
