Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Fishing Elephant

Also known as: Outrider Tiger

Description

Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan. They rely on consistent TTPs, including payload and communication patterns, while occasionally incorporating new techniques such as geo-fencing and hiding executables within certificate files. Their tool of choice is AresRAT, which they deliver through platforms like Heroku and Dropbox. Recently, they have shifted their focus to government and diplomatic entities in Turkey, Pakistan, Bangladesh, Ukraine, and China.

AI Analysis

· 1 week ago

Executive Summary

Fishing Elephant is a persistent threat actor targeting South Asian regions, notably Bangladesh and Pakistan, with recent shifts towards government entities in Turkey, Ukraine, China, and others. Utilizing AresRAT delivered via platforms like Heroku and Dropbox, they employ advanced techniques such as geo-fencing and hiding executables within certificate files, indicating a capability to adapt their attack methods.

Goals & Targeting

Fishing Elephant's strategic objectives appear to focus on gaining access to sensitive data or causing disruption within targeted nations. Their geographic shifts suggest a potential interest in espionage or diplomatic communications, targeting regions with significant geopolitical interests.

Enhanced Description

Fishing Elephant operates with a focus on South Asian regions, initially targeting Bangladesh and Pakistan. Their operations exhibit consistent TTPs, including payload delivery through Heroku and Dropbox, alongside the use of AresRAT. Notably, they have incorporated advanced techniques such as geo-fencing to evade detection and hide executables within certificate files. Recently, their targets have expanded to include government and diplomatic entities in Turkey, Pakistan, Bangladesh, Ukraine, and China. This shift suggests an evolving strategy aimed at accessing sensitive information or disrupting critical operations.

Key Capabilities

  • Use of AresRAT for remote control and persistence
  • Consistent TTPs with occasional technique updates
  • Geo-fencing for regional targeting
  • Payload delivery via legitimate platforms like Heroku and Dropbox

MITRE ATT&CK Tactics

Initial Access
Persistence
Lateral Movement

ATT&CK Techniques

T1566.003
T1071.004

Software / Tooling

AresRAT

Campaigns & Victims

Fishing Elephant maintains a steady operational tempo, with campaigns persisting across targeted regions. Their recent shift towards government entities indicates a focus on high-value targets for potential intelligence gathering or disruption.

IOC Patterns

  • Use of Heroku and Dropbox for payload delivery
  • Hiding executables within certificate files

Recommended Actions

  • Monitor network traffic for C2 communications
  • Conduct regular user training to recognize phishing attempts
  • Secure RDP access with strong authentication measures

Suggested Tags

APT
Spear Phishing
Espionage
Government Sector

Confidence Assessment

Low confidence due to gaps in primary motivation and specific TTP details. However, the information on tools and targets is sufficient for mitigation strategies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
APT
Spear Phishing
Espionage
Government Sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.