Fishing Elephant
Fishing Elephant is an India-linked cyber-espionage threat actor tracked in reporting alongside the cluster Arctic Wolf calls Sloppy Lemming and also connected by researchers to Outrider Tiger. Reporting cited in the source material links Fishing Elephant to campaigns targeting organizations in South and Southeast Asia, with a focus on nuclear, defense, logistics, and telecommunications providers; broader Sloppy Lemming reporting also describes targeting of nuclear-regulatory organizations, defense firms, and critical infrastructure in Pakistan and Bangladesh. One cited campaign attributed to Fishing Elephant used phishing to deliver AresRAT. The source material further states that India-linked espionage activity in this ecosystem relies heavily on phishing and credential theft, and that related activity has used PDF lures, macro-enabled Excel documents, Rust-based tooling, and cloud/edge-hosted command-and-control infrastructure such as Cloudflare Workers. Kaspersky also lists Fishing Elephant among India-nexus groups and distinguishes other clusters such as Dropping Elephant and Mysterious Elephant as separate actors.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- government
- diplomacy
Tradecraft
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
India-nexus cyber-espionage group reported as linked/overlapping with Sloppy Lemming; described as focusing on nuclear, defense, logistics, and telecommunications providers.
Uses cloud platforms (Heroku, Dropbox) to deliver AresRAT; added geo-fencing and hiding executables within certificate files to hinder analysis; targets government and diplomatic entities across multiple countries.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.