logo

SloppyLemming Espionage Campaign Targets Pakistan, Bangladesh with BurrowShell Backdoor and Rust RAT

ID: 18300b81-840c-5452-b211-546aa9ec5977

STIX ID: report--18300b81-840c-5452-b211-546aa9ec5977

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SloppyLemming (aka Outrider Tiger/Fishing Elephant) conducted a year-long espionage campaign against Pakistani and Bangladeshi government and critical infrastructure using spear‑phishing to deliver a BurrowShell backdoor and a Rust-based keylogger/RAT via DLL sideloading and ClickOnce manifests; the group scaled Cloudflare Workers for payload delivery and C2, leaked staged malware through misconfigured Workers, and utilized both custom implants and frameworks like Havoc, prompting specific detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.