logo

'SloppyLemming' APT Abuses Cloudflare Service in Pakistan Attacks

ID: b0b8937d-83e2-5b57-bd57-7f6f5bbf2174

STIX ID: report--b0b8937d-83e2-5b57-bd57-7f6f5bbf2174

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-09-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

SloppyLemming, an APT linked to India, is conducting a multi-stage espionage campaign across South Asia that begins with spear-phishing and abuses cloud services (notably Cloudflare Workers) to host phishing pages (via a tool called CloudPhish), harvest credentials (exfiltrated to Discord), and deliver a RAT — including chains that exploit CVE-2023-38831 in WinRAR — against government, law enforcement, energy, and critical infrastructure targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.