ModifiedElephant
ModifiedElephant is a threat actor tracked by SentinelLabs that has operated since at least 2012 and was still active at the time of reporting. SentinelLabs attributed roughly a decade of targeted activity to the group, primarily against human rights activists, human rights defenders, academics, journalists, and lawyers across India. The reported objective was long-term surveillance and, in some cases, planting incriminating digital evidence on victim systems. SentinelLabs linked the actor to targeted attacks associated with the Bhima Koregaon case and assessed that its activity aligns sharply with Indian state interests, while stopping short of definitive attribution. ModifiedElephant primarily used spearphishing emails sent from free webmail providers such as Gmail and Yahoo, often repeatedly targeting the same individuals over extended periods. Delivery methods included malicious attachments and externally hosted files, with lures themed around activism, climate change, politics, and public service. The actor used executable attachments with fake double extensions in earlier activity and later shifted to less obvious file types including .doc, .pps, .docx, .rar, and password-protected .rar archives. Reported exploit use included CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, and CVE-2015-1641. The primary malware families associated with ModifiedElephant were the commodity RATs NetWire and DarkComet. The actor also used Visual Basic keyloggers and, in some campaigns, an unidentified Android commodity trojan delivered as an APK alongside NetWire payloads. SentinelLabs reported that the group often used new malware samples for individual infection attempts, though some payloads were reused across targets. A forensic report cited by SentinelLabs found that the file "Ltr_1804_to_cc.pdf" was delivered via a NetWire remote session associated with the actor, and SentinelLabs observed nearly identical evidence creation and organization across multiple unrelated victim systems within a short time window. Reported overlaps include infrastructure overlap via new-agency[.]us with Operation Hangover, and some victims were also targeted by other surveillance clusters, including SideWinder phishing and NSO Group Pegasus. Known alias in the provided content: modifiedelephant.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Academia & Research
- Non-Governmental Organizations
Where they target
Geographies tied to known operations.
- 🇮🇳 India
Tradecraft
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice.
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice.
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice.
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice.
Observables
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts targeted attacks against civil society and legal/academic individuals in India, with the objective of planting incriminating digital evidence; active since at least 2012.
Conducts long-term surveillance and spearphishing campaigns against activists, human rights defenders, journalists, academics, and lawyers in India, using commodity RATs and keyloggers to compromise systems and plant incriminating digital evidence prior to arrests.
Referenced as a separate APT that later targeted an Indian individual also seen in Appin-related activity; no further detail is provided here.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.