Malware, Threat Intelligence

SloppyLemming targets Pakistan and Bangladesh with new malware

Laptop screen showing malware warning sign with digital circuit background on desk in modern office environment with natural light and creative concept.

As reported by The Hacker News, the threat activity cluster known as SloppyLemming has been linked to a new wave of cyberattacks targeting government entities and critical infrastructure operators in Pakistan and Bangladesh. These attacks, which occurred between January 2025 and January 2026, highlight the evolving tactics of sophisticated threat actors, according to Arctic Wolf.

The SloppyLemming group employed two distinct attack chains to deploy malware. One chain utilized spear-phishing emails containing PDF lures and macro-enabled Excel documents. These led victims to ClickOnce application manifests that deployed a malicious loader, which in turn executed BurrowShell, a full-featured backdoor capable of file manipulation, remote shell execution, and network tunneling. The second attack chain used Excel documents with malicious macros to deliver a Rust-based keylogger, also incorporating port scanning and network enumeration features. This evolution includes the use of the Rust programming language, a departure from previous reliance on traditional compiled languages and frameworks like Cobalt Strike and Havoc.

The targeting of critical sectors like energy, telecommunications, and defense in South Asia suggests intelligence gathering aligned with regional strategic competition. The observed increase in Cloudflare Workers domains used for command-and-control infrastructure, alongside the dual payload strategy, indicates a flexible and adaptive threat actor.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds