logo

Indian APT 'Sloppy Lemming' Targets Defense, Critical Infrastructure

ID: 29260f8d-fd64-5da6-916e-f9fa5dbf1272

STIX ID: report--29260f8d-fd64-5da6-916e-f9fa5dbf1272

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Robert Lemos

...
...

Arctic Wolf and other researchers warn that the India-linked APT "Sloppy Lemming" has ramped up cyber-espionage against nuclear-regulatory, defense, telecommunications and logistics targets in Pakistan and Bangladesh, migrating from off-the-shelf tools to custom Rust-based malware (including a keylogger), expanding Cloudflare Workers-based C2 infrastructure to over 100 domains, and using phishing (PDF redirects and macro-enabled Excel) to gain access—despite operational security mistakes that have exposed parts of its infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.