logo

SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains

ID: aa749800-b81f-54c4-8409-a0bf76e80d45

STIX ID: report--aa749800-b81f-54c4-8409-a0bf76e80d45

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Arctic Wolf links SloppyLemming to a Jan 2025–Jan 2026 campaign targeting government and critical infrastructure in Pakistan and Bangladesh using spear-phishing with ClickOnce and macro-laden Excel to deploy an in-memory backdoor (BurrowShell) and a Rust-based keylogger; the actor used DLL side-loading, Havoc C2, RC4-protected payloads, and extensive Cloudflare Workers typo-squatted domains to support operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.