Arctic Wolf reported an India-nexus espionage campaign attributed to SloppyLemming (aka Outrider Tiger / Fishing Elephant) targeting government entities and critical infrastructure operators in Pakistan and Bangladesh (with additional reporting noting Sri Lanka). The activity, tracked from January 2025 to January 2026, used two main infection chains: (1) PDF lure documents that redirected victims to ClickOnce manifests, deploying a DLL sideloading package using a legitimate .NET runtime executable (NGenTask.exe) alongside a malicious loader (mscorsvc.dll) that decrypted and executed a custom x64 shellcode implant dubbed BurrowShell; and (2) macro-enabled Excel lures delivering a Rust-based keylogger/recon tool with capabilities including port scanning and network enumeration. BurrowShell was described as a full-featured backdoor enabling file operations, screenshot capture, remote shell execution, and SOCKS proxy tunneling, while attempting to blend in by masquerading C2 as Windows Update traffic and using RC4 with a 32-character key for payload protection.
Infrastructure analysis tied the campaign to 112 Cloudflare Workers domains registered during the tracking period—an expansion in scale compared to prior public reporting—and included government-themed domain naming intended to increase victim trust. Reported targets included Pakistani nuclear regulatory and defense-adjacent organizations (e.g., the Pakistan Nuclear Regulatory Authority, Pakistan Navy, and logistics/telecom entities) and Bangladeshi energy and financial-sector organizations (including power grid/utility operators). Arctic Wolf assessed the actor as moderately capable, citing multi-stage execution and defense evasion knowledge alongside operational security lapses (e.g., exposed directories), and noted the activity as an expansion of threat activity previously identified publicly by Cloudflare.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On March 2, 2026, Arctic Wolf published a report attributing the year-long espionage campaign to SloppyLemming with moderate confidence. The report detailed the BurrowShell backdoor, the Rust-based RAT/keylogger, targeting in Pakistan and Bangladesh, and the actor's expanded use of Cloudflare Workers infrastructure.
Arctic Wolf said the activity it analyzed ran from January 2025 through January 2026. By the end of that period, the actor had used 112 Cloudflare Workers domains, representing a substantial expansion of its delivery and command-and-control infrastructure.
At some point during the 2025-2026 campaign, researchers identified three open-directory misconfigurations on SloppyLemming infrastructure. The exposed directories revealed staged malware and components associated with the Havoc framework, highlighting operational security failures by the actor.
In October 2025, Trellix published reporting on a SideWinder campaign whose tactics, techniques, and procedures partially overlapped with activity later documented by Arctic Wolf. Arctic Wolf noted the similarities but assessed key differences that supported tracking SloppyLemming as a distinct cluster.
Also during the campaign, SloppyLemming used macro-enabled Excel lures to deliver a second malware chain involving a renamed legitimate Microsoft binary and a sideloaded Rust-based payload. The malware provided keylogging, command execution, file operations, screenshots, port scanning, and network enumeration.
During the campaign, SloppyLemming used PDF lures that redirected victims to ClickOnce manifests, leading to DLL sideloading via a renamed legitimate .NET binary and execution of the BurrowShell backdoor. BurrowShell supported remote shell access, file operations, screenshots, and SOCKS proxying while disguising command-and-control traffic as Windows Update over HTTPS.
Around January 2025, the India-nexus threat actor SloppyLemming began a cyber-espionage campaign targeting government agencies and critical infrastructure in Pakistan and Bangladesh, with some reporting also noting Sri Lanka. The operation relied on spear-phishing and social engineering to reach victims in sectors including defense, telecom, energy, finance, and nuclear regulation.
In September 2024, Cloudflare reported abuse of Cloudflare Workers infrastructure linked to activity associated with CrowdStrike's India-nexus actor Outrider Tiger. Arctic Wolf later cited this as prior related reporting and noted a major increase in such domains afterward.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcearcticwolf.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.