'SloppyLemming' APT Abuses Cloudflare Service in Pakistan Attacks
ID: b0b8937d-83e2-5b57-bd57-7f6f5bbf2174
STIX ID: report--b0b8937d-83e2-5b57-bd57-7f6f5bbf2174
Feed Name: Dark Reading
Threat Score
SloppyLemming, an APT linked to India, is conducting a multi-stage espionage campaign across South Asia that begins with spear-phishing and abuses cloud services (notably Cloudflare Workers) to host phishing pages (via a tool called CloudPhish), harvest credentials (exfiltrated to Discord), and deliver a RAT — including chains that exploit CVE-2023-38831 in WinRAR — against government, law enforcement, energy, and critical infrastructure targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
