Frantic Tiger, tracked by Proofpoint as TA395, is an India-aligned cyber-espionage threat cluster operating within the broader South Asian intrusion ecosystem. It has been observed sharing lure themes, compromised accounts, and occasionally overlapping victimology with Sidewinder (TA399), suggesting some degree of shared resourcing or coordinated tasking among India-nexus actors. Frantic Tiger is distinct from other India-linked clusters such as Bitter (TA397), Sloppy Lemming, Dropping Elephant, and Mysterious Elephant, although researchers have noted partial overlaps across parts of this ecosystem. Available reporting ties Frantic Tiger to phishing-centric espionage tradecraft common among India-linked operators. The broader cluster set it belongs to is characterized by social-engineering-driven initial access, use of compromised accounts in targeting operations, and credential-focused collection rather than reliance on zero-day exploitation. High-confidence public detail specific to Frantic Tiger’s malware families, persistence mechanisms, or post-compromise tooling remains limited in the supplied material. Frantic Tiger should be understood as part of a regional espionage landscape focused on South Asian strategic interests, with operational patterns that intersect with other India-aligned groups while remaining a separately tracked actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.