SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains
ID: aa749800-b81f-54c4-8409-a0bf76e80d45
STIX ID: report--aa749800-b81f-54c4-8409-a0bf76e80d45
Feed Name: The Hacker News
Threat Score
Arctic Wolf links SloppyLemming to a Jan 2025–Jan 2026 campaign targeting government and critical infrastructure in Pakistan and Bangladesh using spear-phishing with ClickOnce and macro-laden Excel to deploy an in-memory backdoor (BurrowShell) and a Rust-based keylogger; the actor used DLL side-loading, Havoc C2, RC4-protected payloads, and extensive Cloudflare Workers typo-squatted domains to support operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
