Also known as: tracked as, APT-K-47, Cranberry, Ganeshvari, has launched a cyber-espionage, UNC5174 by Mandiant, GOREVERSE
Mysterious Elephant (also known as APT‑K‑47, Cranberry, Ganeshvari, UNC5174, GOREVERSE) is a sophisticated threat actor that appears to be state‑backed or affiliated with a state‑sponsored supply‑chain. From its inception in 2023 the group has systematically expanded across South‑Asian and neighbouring countries (China, India, Pakistan, Ukraine, North Korea, DPRK), targeting ministries of foreign affairs, defense, police, telecom operators, critical energy assets, financial‐services firms, universities and media houses. The actor’s initial access vectors are predominantly spearphishing emails with culturally resonant themes such as Hajj or election notifications, using malicious attachments in the form of CHM files, RAR archives embedding MSC executables or VBScript hosts. Once inside, the malware chain leverages pre‑disclosure CVE exploits (e.g., CVE‑2024‑8963/8190 against Ivanti Cloud Services, CVE‑2024‑43572 in mmc.exe) to inject code into privileged services and network appliances. After establishing a foothold, Mysterious Elephant deploys a layered toolkit that includes custom RATs like ORPCBackdoor, AsyncShell, GOREVERSE, BabShell and MemLoader; open‑source modules such as GOREshell (a PHP web shell) and PowerShell scripts. Persistence is achieved via DLL hijacking, PowerShell‑scheduled tasks, and scheduled task creation (LNK, CHM, MSC, IQY files). The actor’s command and control relies on a shared Nimbo‑C2 framework, which delivers HTTP(S) beacons that encode victim computer names, usernames and exfiltration bundles. Operationally the group regularly harvests credentials from Chrome, captures WhatsApp messages and other documents, wraps them in encrypted 7‑Zip archives, then exfiltrates over TLS/HTTPS or DNS‑over‑HTTPS channels. The use of Let’s Encrypt certificates for outbound traffic enables it to evade basic SSL inspection. Collaboration with other India/CN actors (Origami Elephant, Confucius, SideWinder) suggests a shared infrastructure and tool repository, implying a broader state‑federal cyber espionage program directed at extracting diplomatic, military and commercial secrets from the region.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Mysterious Elephant (APT‑K‑47) is a rapidly evolving South‑Asian APT that emerged in 2023 and targets high‑value government, defense, infrastructure and commercial organizations across Asia‑Pacific. The group relies on spearphishing, zero‑day CVE exploitation and malicious document delivery to gain initial access, then deploys a diverse toolkit of RATs, web shells and custom backdoors for persistence, lateral movement and data exfiltration.
Goals & Targeting
Mysterious Elephant’s primary objective is strategic intelligence gathering on government agencies, defense establishments and critical infrastructure operators in targeted countries. By harvesting credentials, communications, documents and system metadata it enables geopolitical influence operations and potential sabotage or disruption scenarios. The selection of victims—often ministries of foreign affairs, police CMS systems and telecom backbones—indicates a focus on obtaining policy insight and facilitating subsequent clandestine actions. The group’s repeated use of culturally tailored spearphishing themes shows an intent to maximize engagement rates among specific populations. Their rapid exploitation of zero‑day vulnerabilities before disclosure indicates aggressive reconnaissance efforts designed to gain early, high‑privilege access. All indications point to a long‑term, state-backed mission aimed at enabling policy influence and operational decision advantage for the sponsoring nation rather than simply conducting conventional cybercrime.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first appearance in 2023, Mysterious Elephant has demonstrated a steady escalation of capabilities and breadth. Initial campaigns focused on exploiting newly disclosed CVEs (e.g., CVE-2024-8963/8190) before public release, showing an aggressive approach to zero‑day exploitation. Overlap with other India/CN APTs reveals a shared supply chain where code, C2 infrastructure and even malware samples such as GOREVERSE are reused across campaigns. Victim profiles cover a wide range of sectors but consistently include high‑profile government bodies, defense ministries, telecommunication backbones and critical energy or transport infrastructures in CN, PK, IN, UA, KP, KR. These targets align with typical geopolitical objectives of state actors seeking policy influence or strategic advantage. Notable past operations include the distribution of ShadowPad to more than 70 global organizations, the deployment of GOREVERSE across government networks, and multiple spearphishing campaigns that leveraged Hajj‑themed content. The group's operational tempo shows rapid tool development, exploitation diversification (moving from CHM-based delivery to RAR+MSC payloads), and increased use of encrypted exfiltration channels. The evidence points to a long‑term commitment to espionage rather than opportunistic malware campaigns, with an emphasis on data acquisition from key governmental players in strategic regions.
IOC Patterns
Recommended Actions
Confidence Assessment
The confidence in the compiled intelligence is moderate to high regarding technical capabilities, tactics and tools because multiple independent reports corroborate these findings. Attribution remains uncertain due to shared codebases and overlapping infrastructure with other India/CN actors; however the concentration of activity in the South‑Asian region and use of culturally tailored spearphishing suggests a state-backed program. Gaps exist around the exact motivation hierarchy, long‑term objective planning, and the complete extent of cross‑group collaboration.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
57
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics