Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mysterious Elephant

Mysterious Elephant

TLP:CLEAR
Active

Also known as: tracked as, APT-K-47, Cranberry, Ganeshvari, has launched a cyber-espionage, UNC5174 by Mandiant, GOREVERSE

Description

Mysterious Elephant (also known as APT‑K‑47, Cranberry, Ganeshvari, UNC5174, GOREVERSE) is a sophisticated threat actor that appears to be state‑backed or affiliated with a state‑sponsored supply‑chain. From its inception in 2023 the group has systematically expanded across South‑Asian and neighbouring countries (China, India, Pakistan, Ukraine, North Korea, DPRK), targeting ministries of foreign affairs, defense, police, telecom operators, critical energy assets, financial‐services firms, universities and media houses. The actor’s initial access vectors are predominantly spearphishing emails with culturally resonant themes such as Hajj or election notifications, using malicious attachments in the form of CHM files, RAR archives embedding MSC executables or VBScript hosts. Once inside, the malware chain leverages pre‑disclosure CVE exploits (e.g., CVE‑2024‑8963/8190 against Ivanti Cloud Services, CVE‑2024‑43572 in mmc.exe) to inject code into privileged services and network appliances. After establishing a foothold, Mysterious Elephant deploys a layered toolkit that includes custom RATs like ORPCBackdoor, AsyncShell, GOREVERSE, BabShell and MemLoader; open‑source modules such as GOREshell (a PHP web shell) and PowerShell scripts. Persistence is achieved via DLL hijacking, PowerShell‑scheduled tasks, and scheduled task creation (LNK, CHM, MSC, IQY files). The actor’s command and control relies on a shared Nimbo‑C2 framework, which delivers HTTP(S) beacons that encode victim computer names, usernames and exfiltration bundles. Operationally the group regularly harvests credentials from Chrome, captures WhatsApp messages and other documents, wraps them in encrypted 7‑Zip archives, then exfiltrates over TLS/HTTPS or DNS‑over‑HTTPS channels. The use of Let’s Encrypt certificates for outbound traffic enables it to evade basic SSL inspection. Collaboration with other India/CN actors (Origami Elephant, Confucius, SideWinder) suggests a shared infrastructure and tool repository, implying a broader state‑federal cyber espionage program directed at extracting diplomatic, military and commercial secrets from the region.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Media
Information technology
Transportation
Financial services
Manufacturing
Energy
Critical infrastructure
Education
Hospitality

Targeted Countries / Regions

CN
PK
IN
UA
KP
KR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 7 hours ago

Executive Summary

Mysterious Elephant (APT‑K‑47) is a rapidly evolving South‑Asian APT that emerged in 2023 and targets high‑value government, defense, infrastructure and commercial organizations across Asia‑Pacific. The group relies on spearphishing, zero‑day CVE exploitation and malicious document delivery to gain initial access, then deploys a diverse toolkit of RATs, web shells and custom backdoors for persistence, lateral movement and data exfiltration.

Goals & Targeting

Mysterious Elephant’s primary objective is strategic intelligence gathering on government agencies, defense establishments and critical infrastructure operators in targeted countries. By harvesting credentials, communications, documents and system metadata it enables geopolitical influence operations and potential sabotage or disruption scenarios. The selection of victims—often ministries of foreign affairs, police CMS systems and telecom backbones—indicates a focus on obtaining policy insight and facilitating subsequent clandestine actions. The group’s repeated use of culturally tailored spearphishing themes shows an intent to maximize engagement rates among specific populations. Their rapid exploitation of zero‑day vulnerabilities before disclosure indicates aggressive reconnaissance efforts designed to gain early, high‑privilege access. All indications point to a long‑term, state-backed mission aimed at enabling policy influence and operational decision advantage for the sponsoring nation rather than simply conducting conventional cybercrime.

Enhanced Description

Key Capabilities

  • Spearfishing emails with culturally resonant themes (e.g., Hajj) using malicious CHM or RAR attachments
  • Exploits zero‑day CVEs on privileged services such as mmc.exe, Ivanti Cloud Appliances and government mail gateways
  • Deploys custom and open‑source RATs including ORPCBackdoor, AsyncShell, GOREVERSE, reverse_ssh, BabShell, MemLoader, and webshells (GOREshell, PHP)
  • Establishes persistence via PowerShell‑created scheduled tasks, DLL hijacking, LNK/CHM/MSC file execution
  • Uses Nimbo–C2 or similar frameworks for command‑and‑control with HTTP(S) beaconing that encodes victim details
  • Exfiltrates data through encrypted bundles over HTTPS/TLS or DNS-over-HTTPS, sometimes using Let’s Encrypt certificates
  • Harvests credentials from browsers and messaging apps (Chrome bookmarks, WhatsApp documents)
  • Shares infrastructure and malware code with other India/CN state‑backed actors such as Origami Elephant, Confucius, SideWinder

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Lateral Movement
Exfiltration
Command and Control

ATT&CK Techniques

T1005
T1078
T1059.001
T1059.003
T1086
T1105
T1053.005
T1203
T1566.001

Software / Tooling

ORPCBackdoor
AsyncShell
GOREVERSE
reverse_ssh
BabShell
MemLoader
GOREshell
WebShell PHP
Nimbo‑C2
ShadowPad
AstraShell

Campaigns & Victims

Since its first appearance in 2023, Mysterious Elephant has demonstrated a steady escalation of capabilities and breadth. Initial campaigns focused on exploiting newly disclosed CVEs (e.g., CVE-2024-8963/8190) before public release, showing an aggressive approach to zero‑day exploitation. Overlap with other India/CN APTs reveals a shared supply chain where code, C2 infrastructure and even malware samples such as GOREVERSE are reused across campaigns. Victim profiles cover a wide range of sectors but consistently include high‑profile government bodies, defense ministries, telecommunication backbones and critical energy or transport infrastructures in CN, PK, IN, UA, KP, KR. These targets align with typical geopolitical objectives of state actors seeking policy influence or strategic advantage. Notable past operations include the distribution of ShadowPad to more than 70 global organizations, the deployment of GOREVERSE across government networks, and multiple spearphishing campaigns that leveraged Hajj‑themed content. The group's operational tempo shows rapid tool development, exploitation diversification (moving from CHM-based delivery to RAR+MSC payloads), and increased use of encrypted exfiltration channels. The evidence points to a long‑term commitment to espionage rather than opportunistic malware campaigns, with an emphasis on data acquisition from key governmental players in strategic regions.

IOC Patterns

  • CHM files used as malicious payload carriers
  • RAR archives embedding MSC executables that trigger mmc.exe
  • Cmd shell execution via asynchronous programming (AsyncShell)
  • Spearphishing attachments or malicious documents PowerShell scripts for execution, persistence and exfiltration
  • Backdoors such as GOREVERSE, ORPCBackdoor, reverse_ssh, BabShell
  • Webshells including GOREshell PHP
  • ShadowPad samples in wide deployments
  • CVE‑based exploitation of mmc.exe (GrimResource) and other public services
  • HTTP(S) beacon traffic encoding victim details Scheduled task creation via PowerShell

Recommended Actions

  • Apply timely patches for known CVEs (CVE-2024-8963, CVE-2024-8190, CVE-2024-43572, etc.) before public disclosure.
  • Deploy detection rules for known backdoor signatures such as GOREVERSE, ORPCBackdoor, reverse_ssh and BabShell. Monitor outbound HTTP(S) beaconing patterns and anomalous PowerShell activity to detect Nimbo‑C2 or other C2 traffic. Block or quarantine RAR files containing embedded MSC executables; enforce policy to block execution of mmc.exe from untrusted sources. Implement advanced phishing filters, user education campaigns, and email sandboxing focused on spearphishing attachments. Detect and alert on creation of scheduled tasks via PowerShell or other persistence mechanisms. Inspect TLS/SSL traffic, including Certif‑ficate validation and DoH activity, to reveal Let’s Encrypt usage for data exfiltration. Deploy endpoint protection that detects known webshells (GOREshell), JavaScript injection, and credential harvesting scripts.
  • suggested_tags
  • AIT
  • APT-K-47
  • Mysterious Elephant
  • Asynshell
  • ORPCBackdoor
  • PowerShell
  • GoSerpent
  • ScatterBrain
  • GoreShell
  • APT15
  • Ke3Chang
  • NylonTyphoon
  • UNC5174
  • TA397
  • GOREVERSE
  • ShadowPad
  • CVE-2024-8963
  • CVE-2024-8190
  • CVE-2023-46747
  • CVE-2024-1709
  • Spearphishing
  • ScheduledTaskPersistence
  • CVEExploit
  • PowerShellExecution
  • GrimResource

Confidence Assessment

The confidence in the compiled intelligence is moderate to high regarding technical capabilities, tactics and tools because multiple independent reports corroborate these findings. Attribution remains uncertain due to shared codebases and overlapping infrastructure with other India/CN actors; however the concentration of activity in the South‑Asian region and use of culturally tailored spearphishing suggests a state-backed program. Gaps exist around the exact motivation hierarchy, long‑term objective planning, and the complete extent of cross‑group collaboration.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 8 Filename 6 URL 2 IPv4 Address 4

References

  1. www.sentinelone.com — Cited by web research for: UNC5174 by Mandiant
  2. www.sentinelone.com — Cited by web research for: ShadowPad
  3. apt.etda.or.th — Cited by web research for: Payload
  4. www.kaspersky.com — Cited by web research for: PowerShell
  5. apt.etda.or.th — Cited by web research for: Cobalt
  6. www.proofpoint.com — Cited by web research for: Scheduled Tasks
  7. https://medium.com/@knownsec404team/unveiling-the-past-and-present-of-apt-k-47-weapon-asyncshell-5a98f75c2d68 — Cited by AI analysis.
  8. https://medium.com/@knownsec404team/apt-k-47-mysterious-elephant-a-new-apt-organization-in-south-asia-5c66f954477 — Cited by AI analysis.
  9. https://www.kaspersky.com/about/press-releases/an-elephant-in-the-room-kaspersky-detects-new-myste — Cited by AI analysis.

Intel Summary

9

Techniques

57

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

APT
espionage
government-sector
South-Asia
spear-phishing
RAT
custom-malware

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.