Monday , September 14 2026
SloppyLemming

BurrowShell Backdoor Found
India linked “SloppyLemming” target Bangladesh & Pakistan Critical Systems

An India-nexus threat actor operated an extensive cyber espionage campaign deploying BurrowShell and Rust-Based RAT, targeting government entities and critical infrastructure operators in Pakistan and Bangladesh. Arctic Wolf has been tacking the campaign conducted by “SloppyLemming” over the last 12 month.

Source: Arctic Wolf

Arctic Wolf said, the campaign impersonated Pakistani and Bangladeshi government agencies and organizations such as Dhaka Electric Supply Company, Power Grid Company of Bangladesh, Bangladesh Bank, Pakistan Nuclear Regulatory Authority and so on.

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

From January 2025 to January 2026, Arctic Wolf monitored a significant cyber espionage campaign believed to be carried out by SloppyLemming (also known as Outrider Tiger and Fishing Elephant), a group linked to India, targeting government and critical infrastructure in Pakistan and Bangladesh.

The campaign used two separate attack strategies. The first involved sending PDF documents that led victims to ClickOnce application manifests, which installed a DLL sideloading package containing a legitimate Microsoft .NET runtime (NGenTask.exe) and a harmful loader (mscorsvc.dll). This loader then decrypted and executed a custom x64 implant called BurrowShell, identified by Arctic Wolf.

BurrowShell is a comprehensive backdoor that allows attackers to manipulate files, capture screenshots, execute remote shells, and create SOCKS proxies for network tunneling. It disguises its command-and-control traffic as Windows Update communications and uses RC4 encryption with a 32-character key for security.

Figure 13: Execution chain diagram showing complete attack flow from PDF lure to C2 communication.

A secondary attack uses macro-enabled Excel files to deliver a Rust keylogger that can scan ports and enumerate networks. This marks a significant upgrade in SloppyLemming’s tools, which previously relied on traditional languages and simulation frameworks like Cobalt Strike, Havoc, and the bespoke NekroWire RAT.

Arctic Wolf reported that 112 Cloudflare Workers domains were registered from January 2025 to January 2026, up from 13 documented in September 2024. Three of these domains had open directory misconfigurations that exposed malware, including Havoc framework loaders with unique RC4 encryption keys. The highest number of registrations happened in July 2025, with 42 new domains, indicating increased activity.

Arctic Wolf believes with moderate confidence that this activity is linked to SloppyLemming. This is based on the use of Cloudflare Workers for government-related typo-squatting, deployment of the Havoc C2 framework associated with this actor, DLL sideloading techniques that match known methods, and a focus on South Asian government and infrastructure targets.

The campaign targeted Pakistani nuclear regulators, defense logistics, and telecommunications, as well as Bangladeshi energy and financial sectors, reflecting intelligence priorities in South Asia. For technical details click here.

AI-Powered “iCyberHunt” explores Bangladeshi market

Check Also

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems …