Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SloppyLemming

Also known as: Outrider Tiger, Fishing Elephant, Barium, Brass Typhoon, APT28, Fancy Bear, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, APT43, UNC2970, Razor Tiger, Rattlesnake, T-APT-04, Wicked Panda, Wicked Spider, Earth Baku, Axiom, Blackfly, Bronze Atlas, HOODOO, Red Kelpie, TA415, Winnti, APT41, ClientEndPoint, APT33, Elfin, Refined Kitten, Head Mare, Bloody Wolf, SkyCloak, TG-2633, Winnti Umbrella, BRONZE ATLAS

Description

SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, malware delivery and command and control (C2). This actor conducts extensive operations targeting Pakistani, Sri Lanka, Bangladesh, and China. Industries targeted include government, law enforcement, energy, telecommunications, and technology entitie

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Energy
Manufacturing
Transportation
Education
Critical infrastructure
Telecommunications
Media
Aerospace
Construction
Maritime
Healthcare
Information technology
Chemical
Oil gas
Retail
Aviation
Nuclear
Pharmaceutical
Utilities
Gaming
Think tank
Entertainment
Food agriculture
Mining
Technology

Targeted Countries / Regions

PK
IN
US
RU
UA
AE
TW
PL
GB
DE
CN
TR
KZ
BR
IL
KR
JP
NL
ES
IT
RO
SG
AU
EG
VN
BY
NG
SA
MX

AI Analysis

· 1 week ago

Executive Summary

SloppyLemming is a sophisticated cyber threat actor leveraging cloud service providers for malicious activities such as credential harvesting, malware delivery, and command and control (C2). Primarily targeting South Asian countries including Pakistan, Sri Lanka, Bangladesh, and China, SloppyLemming focuses on critical sectors like government, energy, telecommunications, and technology. Their operations demonstrate a high level of technical proficiency and adaptability in compromising cloud infrastructure.

Goals & Targeting

SloppyLemming's strategic objectives appear to be centered on compromising critical infrastructure and sensitive data within targeted countries and sectors. Their focus on South Asian nations and industries like government and energy suggests a potential interest in state secrets, economic advantage, or disrupting national stability. The actor's choice of victims reflects a calculated approach to maximize impact while remaining elusive.

Enhanced Description

SloppyLemming emerges as a significant cyber threat actor who exploits cloud service providers to facilitate their malicious activities. This group conducts extensive campaigns targeting regions such as Pakistan, Sri Lanka, Bangladesh, and China, with a particular focus on sectors including government, law enforcement, energy, telecommunications, and technology. Their ability to use cloud services for credential harvesting, malware delivery, and C2 indicates a high level of technical sophistication and operational adaptability. SloppyLemming's targeting strategy suggests geopolitical or economic interests in these regions, possibly linked to state-sponsored activities or cyber espionage.

Key Capabilities

  • Exploitation of cloud service providers
  • Credential harvesting
  • Malware delivery mechanisms
  • Command and Control (C2) via cloud infrastructure
  • High level of technical proficiency in cloud-based attacks

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement

Software / Tooling

Custom malware for credential harvesting
Cloud exploitation tools

Campaigns & Victims

SloppyLemming has demonstrated persistent and prolonged campaign activity, targeting resource-rich and strategically significant sectors. Their operations suggest an organized and methodical approach to compromising cloud infrastructure and maintaining long-term presence within targeted environments. Notable campaigns include extensive efforts against government agencies and critical national infrastructure in South Asia.

IOC Patterns

  • credential dumping through cloud service exploitation
  • malware delivery via cloud-based platforms
  • unusual C2 communication patterns leveraging cloud services

Recommended Actions

  • Monitor cloud service provider accounts for unauthorized access or异常 activity.
  • Implement multi-factor authentication (MFA) for critical cloud resources.
  • Segment network infrastructure to isolate sensitive systems from less critical ones.
  • Conduct regular threat hunting exercises focused on detecting cloud-based anomalies.

Suggested Tags

APT
espionage
state-sponsored
cloud-attacks

Confidence Assessment

This assessment is based on limited available data about SloppyLemming. While their operational footprint suggests a high level of sophistication, specific details about their tactics, techniques, and procedures (TTPs) remain unclear. Further investigation into their associated tools and exact motivation would enhance understanding.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Barium
  2. ics-cert.kaspersky.com — Cited by web research for: APT28
  3. attack.mitre.org — Cited by web research for: services
  4. attack.mitre.org — Cited by web research for: PowerShell

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting
APT
espionage
state-sponsored
cloud-attacks

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
India (IN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.