Also known as: Outrider Tiger
Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan. They rely on consistent TTPs, including payload and communication patterns, while occasionally incorporating new techniques such as geo-fencing and hiding executables within certificate files. Their tool of choice is AresRAT, which they deliver through platforms like Heroku and Dropbox. Recently, they have shifted their focus to government and diplomatic entities in Turkey, Pakistan, Bangladesh, Ukraine, and China.
Executive Summary
Fishing Elephant is a persistent threat actor targeting South Asian regions, notably Bangladesh and Pakistan, with recent shifts towards government entities in Turkey, Ukraine, China, and others. Utilizing AresRAT delivered via platforms like Heroku and Dropbox, they employ advanced techniques such as geo-fencing and hiding executables within certificate files, indicating a capability to adapt their attack methods.
Goals & Targeting
Fishing Elephant's strategic objectives appear to focus on gaining access to sensitive data or causing disruption within targeted nations. Their geographic shifts suggest a potential interest in espionage or diplomatic communications, targeting regions with significant geopolitical interests.
Enhanced Description
Fishing Elephant operates with a focus on South Asian regions, initially targeting Bangladesh and Pakistan. Their operations exhibit consistent TTPs, including payload delivery through Heroku and Dropbox, alongside the use of AresRAT. Notably, they have incorporated advanced techniques such as geo-fencing to evade detection and hide executables within certificate files. Recently, their targets have expanded to include government and diplomatic entities in Turkey, Pakistan, Bangladesh, Ukraine, and China. This shift suggests an evolving strategy aimed at accessing sensitive information or disrupting critical operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Fishing Elephant maintains a steady operational tempo, with campaigns persisting across targeted regions. Their recent shift towards government entities indicates a focus on high-value targets for potential intelligence gathering or disruption.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to gaps in primary motivation and specific TTP details. However, the information on tools and targets is sufficient for mitigation strategies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics