Mysterious Elephant, an advanced persistent threat (APT) group first identified in 2023, has intensified its cyber-espionage activities targeting government and diplomatic entities in the Asia-Pacific region, with a particular focus on South Asia. The group’s latest campaign, which began in early 2025, demonstrates a significant evolution in their tactics, techniques, and procedures (TTPs). Mysterious Elephant has deployed a new custom backdoor known as MemLoader, alongside other tools such as BabShell and customized open-source utilities, to infiltrate targeted networks. The campaign is notable for its focus on exfiltrating sensitive WhatsApp data, including documents, images, and archive files, from compromised systems. Spear phishing remains a primary initial access vector, with malicious attachments and links used to deliver the malware payloads. Once inside a network, the attackers leverage PowerShell scripts and other living-off-the-land techniques to maintain persistence and evade detection. The group’s malware exhibits code similarities with other APTs, such as Origami Elephant, Confucius, and SideWinder, indicating possible collaboration or shared development resources. Victimology analysis shows a clear targeting of foreign affairs ministries, embassies, and diplomatic missions, particularly those involved in sensitive regional matters. The attackers have also demonstrated the ability to customize their tools for specific environments, increasing the effectiveness of their operations. Infrastructure used in the campaign includes a mix of compromised servers and dedicated command-and-control domains, with indicators of compromise (IOCs) provided to aid in detection. The campaign’s focus on WhatsApp data theft is particularly concerning, as it highlights the attackers’ intent to access private diplomatic communications. Defensive measures recommended include monitoring for the specific IOCs, enhancing email security to block spear phishing attempts, and deploying endpoint detection and response (EDR) solutions capable of identifying the custom tools used. The campaign underscores the growing sophistication of APT operations in the region and the need for heightened vigilance among government and diplomatic organizations. The use of both custom and open-source tools allows Mysterious Elephant to adapt quickly and bypass traditional security controls. The group’s activities are part of a broader trend of state-sponsored cyber-espionage targeting geopolitical interests in South Asia. Organizations are urged to review their security postures and implement layered defenses to mitigate the risk posed by such advanced threats. The ongoing evolution of Mysterious Elephant’s toolset suggests that future campaigns may employ even more sophisticated techniques. Collaboration between targeted organizations and threat intelligence providers is essential to stay ahead of these evolving threats. The campaign serves as a reminder of the persistent and adaptive nature of APT actors operating in the region.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On October 15, 2025, Kaspersky published a public report detailing the actor's TTPs, malware, infrastructure patterns, and indicators of compromise including file hashes and C2 domains and IP addresses. The report documented the group's evolution and current targeting focus.
A key objective of the operation was exfiltration of sensitive data, including files shared through WhatsApp Desktop and Chrome browser data such as cookies and tokens. These artifacts could expose WhatsApp-related information from compromised systems.
Kaspersky reported that MemLoader Edge decrypts and reflectively loads a vxRat-derived backdoor called “VRat.” The malware includes additional sandbox-evasion behavior as part of the group's 2025 toolset.
During the 2025 activity, Mysterious Elephant relied heavily on PowerShell for staging and persistence and used custom or modified open-source tools including the BabShell reverse shell and MemLoader modules. MemLoader HidenDesk was used for in-memory loading, including Remcos RAT, with anti-sandbox and hidden-desktop techniques.
By 2025, the group had evolved its operations to emphasize spear phishing, exploit kits, and malicious documents for initial compromise. The campaign continued to focus on diplomatic and government-related targets in South Asia.
In its earlier operations, the actor used attack chains resembling Confucius tradecraft, including remote template injection and exploitation of CVE-2017-11882 for initial access. These techniques predated the group's later 2025 tooling and delivery changes.
Kaspersky GReAT identified the threat actor it tracks as “Mysterious Elephant” in 2023. The group was observed targeting government and foreign affairs entities in the Asia-Pacific region, especially in South Asia and particularly Pakistan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.