Fishing Elephant is an India-linked cyber-espionage threat actor focused primarily on targets in South Asia, especially Pakistan and Bangladesh. Reporting links the cluster to broader India-nexus activity and, in some research, associates it with or closely connects it to Sloppy Lemming and Outrider Tiger. The actor has been observed targeting nuclear-regulatory organizations, defense entities, logistics and telecommunications providers, and other critical infrastructure sectors, indicating an intelligence-collection mission aligned with regional geopolitical priorities. Fishing Elephant is known for intrusion activity centered on social engineering rather than public reliance on zero-day exploitation. Observed delivery chains include phishing lures using PDF documents that redirect victims and macro-enabled Microsoft Excel documents that deploy malware. The group has been associated with AresRAT and with Rust-based tooling, including custom malware and keylogging components, reflecting a gradual increase in technical sophistication. Researchers have also noted use of cloud and edge-hosted command-and-control infrastructure, including serverless platforms, to improve scalability, resilience, and concealment. The actor’s tradecraft fits a broader pattern seen across several India-aligned espionage clusters: credential theft, lure-driven initial access, and iterative tooling development. At the same time, operational security has not always been strong, and exposed infrastructure has reportedly enabled researcher visibility into parts of its operations. Fishing Elephant should be tracked as part of the wider ecosystem of India-linked espionage actors active across South and Southeast Asia, while recognizing that public reporting does not always fully resolve the boundaries between this cluster and related labels such as Sloppy Lemming and Outrider Tiger.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
India-nexus cyber-espionage group reported as linked/overlapping with Sloppy Lemming; described as focusing on nuclear, defense, logistics, and telecommunications providers.
Continued regional targeting with consistent TTPs; observed adoption of a new keylogger while maintaining established payload/communications patterns.
Uses cloud platforms (Heroku, Dropbox) to deliver AresRAT; added geo-fencing and hiding executables within certificate files to hinder analysis; targets government and diplomatic entities across multiple countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.