Tuesday , August 4 2026
SloppyLemming

BurrowShell Backdoor Found
India linked “SloppyLemming” target Bangladesh & Pakistan Critical Systems

An India-nexus threat actor operated an extensive cyber espionage campaign deploying BurrowShell and Rust-Based RAT, targeting government entities and critical infrastructure operators in Pakistan and Bangladesh. Arctic Wolf has been tacking the campaign conducted by “SloppyLemming” over the last 12 month.

Source: Arctic Wolf

Arctic Wolf said, the campaign impersonated Pakistani and Bangladeshi government agencies and organizations such as Dhaka Electric Supply Company, Power Grid Company of Bangladesh, Bangladesh Bank, Pakistan Nuclear Regulatory Authority and so on.

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

From January 2025 to January 2026, Arctic Wolf monitored a significant cyber espionage campaign believed to be carried out by SloppyLemming (also known as Outrider Tiger and Fishing Elephant), a group linked to India, targeting government and critical infrastructure in Pakistan and Bangladesh.

The campaign used two separate attack strategies. The first involved sending PDF documents that led victims to ClickOnce application manifests, which installed a DLL sideloading package containing a legitimate Microsoft .NET runtime (NGenTask.exe) and a harmful loader (mscorsvc.dll). This loader then decrypted and executed a custom x64 implant called BurrowShell, identified by Arctic Wolf.

BurrowShell is a comprehensive backdoor that allows attackers to manipulate files, capture screenshots, execute remote shells, and create SOCKS proxies for network tunneling. It disguises its command-and-control traffic as Windows Update communications and uses RC4 encryption with a 32-character key for security.

Figure 13: Execution chain diagram showing complete attack flow from PDF lure to C2 communication.

A secondary attack uses macro-enabled Excel files to deliver a Rust keylogger that can scan ports and enumerate networks. This marks a significant upgrade in SloppyLemming’s tools, which previously relied on traditional languages and simulation frameworks like Cobalt Strike, Havoc, and the bespoke NekroWire RAT.

Arctic Wolf reported that 112 Cloudflare Workers domains were registered from January 2025 to January 2026, up from 13 documented in September 2024. Three of these domains had open directory misconfigurations that exposed malware, including Havoc framework loaders with unique RC4 encryption keys. The highest number of registrations happened in July 2025, with 42 new domains, indicating increased activity.

Arctic Wolf believes with moderate confidence that this activity is linked to SloppyLemming. This is based on the use of Cloudflare Workers for government-related typo-squatting, deployment of the Havoc C2 framework associated with this actor, DLL sideloading techniques that match known methods, and a focus on South Asian government and infrastructure targets.

The campaign targeted Pakistani nuclear regulators, defense logistics, and telecommunications, as well as Bangladeshi energy and financial sectors, reflecting intelligence priorities in South Asia. For technical details click here.

AI-Powered “iCyberHunt” explores Bangladeshi market

Check Also

Louisiana

Meta’s louisiana data center to exceed 250 billion price tag

Meta announced on Monday that its data center in Richland Parish, Louisiana, will grow to …