BurrowShell is a custom x64 shellcode-based backdoor (full-featured implant) used in cyber-espionage activity attributed with moderate confidence by Arctic Wolf to the India-nexus threat actor SloppyLemming (aka Outrider Tiger / Fishing Elephant). It was observed in campaigns targeting government entities and critical infrastructure operators in Pakistan and Bangladesh (with related reporting also referencing Sri Lanka) during roughly January 2025–January 2026.
Delivery/execution (observed):
Capabilities (as described in reporting):
Command-and-control (as described in reporting):
Associated infrastructure/IOCs explicitly mentioned in the content:
Targeting noted in the content includes Pakistani nuclear regulatory bodies, defense logistics, and telecommunications infrastructure, and Bangladeshi energy utilities and financial institutions, consistent with an intelligence-collection objective.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SloppyLemming Deploys BurrowShell and Rust-Based RAT to Target Pakistan and Bangladesh
"...delivery of a malicious PDF holding malware known as BurrowShell — a backdoor that allows hackers to take screenshots and manipulate a file system."
"...executed a custom x64 shellcode implant that Arctic Wolf has named BurrowShell. BurrowShell is a full-featured backdoor providing the threat actor with file system manipulation, screenshot capture capabilities, remote shell execution, and SOCKS proxy capabilities for network tunneling."
30 distinct techniques documented for this family, organized by ATT&CK tactic.
“system32.dll (Encrypted Shellcode Payload)… an RC4-encrypted blob containing the final payload.”
“DLLs named mscorsvc.dll, sppc.dll, system32.dll to appear legitimate.”
"...employs RC4 encryption with a 32-character key for payload protection."
"The implant masquerades its command-and-control (C2) traffic as Windows Update service communications..."
“initiates an outbound HTTPS connection… using the WinHTTP API… transmitted via HTTP POST…”
“can activate SOCKS-based tunneling… command set: socks_connect / socks_data / socks_close”
“campaign leverages 112 unique Cloudflare Workers domains… for both payload delivery and C2 communication.”
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Implant/backdoor (shell) used by the SloppyLemming campaign to provide remote access against targets in Pakistan and Bangladesh.
Backdoor/shell implant deployed by SloppyLemming in targeting of Pakistan and Bangladesh.
A full-featured backdoor used after an initial malicious loader, providing file manipulation, remote shell execution, and network tunneling capabilities.
A full-featured backdoor/shellcode implant that supports file system manipulation, screenshot capture, remote shell execution, and SOCKS proxying for network tunneling. It masquerades C2 traffic as Windows Update and uses RC4 encryption with a 32-character key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.