SloppyLemming is an India-nexus cyber-espionage threat actor active since at least 2021 and primarily focused on South Asia. It is also tracked as Outrider Tiger and Fishing Elephant. The actor has targeted government entities, defense organizations, law enforcement, telecommunications providers, energy utilities, financial institutions, and other critical infrastructure, with a strong concentration on Pakistan and Bangladesh and additional activity reported against Sri Lanka, Nepal, Indonesia, China, and other South and East Asian targets. Targeting has included nuclear-regulatory, defense-logistics, and telecom-related organizations, indicating an intelligence-collection mission aligned with Indian state interests. SloppyLemming relies heavily on spear-phishing and social engineering rather than public reporting of zero-day exploitation. Observed delivery chains use trust-based execution and user-assisted infection methods, including PDF lures, macro-enabled Excel documents, ClickOnce application manifests, LNK files, and ISO-based execution chains. The actor has repeatedly used DLL side-loading and legitimate signed Microsoft binaries to launch malicious loaders and payloads, reflecting familiarity with Windows internals and defense-evasion tradecraft. Its tooling has evolved from use of common offensive frameworks such as Cobalt Strike and Havoc, alongside malware families including Ares RAT, WarHawk, and NekroWire RAT, toward more customized implants. Recent operations deployed BurrowShell, a full-featured backdoor with remote shell, file manipulation, screenshot capture, and tunneling capabilities, as well as a Rust-based remote access trojan and keylogger with command execution, persistence, reconnaissance, port-scanning, and network-enumeration functions. Reporting also notes increasing use of Rust and other less common or AI-assisted development approaches across associated malware variants, likely to complicate reverse engineering and diversify tooling. A notable characteristic of SloppyLemming is its expanded use of cloud and edge-hosted infrastructure for payload delivery and command and control, especially Cloudflare Workers and related serverless services. This infrastructure growth has been substantial and supports scalable, disposable, and harder-to-attribute operations. The actor commonly themes infrastructure and lures around government or trusted institutions to increase plausibility. At the same time, researchers have repeatedly noted inconsistent operational security, including exposed directories and other mistakes, which contributed to the “Sloppy” designation despite otherwise moderate sophistication. Analytic reporting describes SloppyLemming as a moderately capable espionage operator that combines adaptive malware development, cloud-based infrastructure, and multi-stage phishing chains with uneven operational discipline. Some reporting notes partial overlap in lure themes or tradecraft with other India-aligned clusters such as Bitter, SideWinder, and Frantic Tiger, but available information supports tracking SloppyLemming as a distinct threat cluster rather than conflating it with those groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses trust-based execution chains including ClickOnce, LNK, and ISO, and develops multiple malware variants in AI-assisted and non-mainstream programming languages.
Activity cluster reported deploying BurrowShell and a Rust-based RAT, targeting Pakistan and Bangladesh.
Deploying BurrowShell and a Rust-based RAT in operations targeting Pakistan and Bangladesh.
Conducting cyber-espionage style intrusions against government and critical infrastructure in South Asia using spear-phishing and malicious Excel/PDF lures to deliver a loader that deploys the BurrowShell backdoor, and a second chain delivering a Rust-based keylogger with port scanning and network enumeration; leveraging Cloudflare Workers domains for C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.