{"id":11096,"date":"2026-03-04T10:04:13","date_gmt":"2026-03-04T10:04:13","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/04\/sloppylemming-espionage-campaign-uses-burrowshell-backdoor-and-rust-rat-to-hit-pakistan-and-bangladesh-targets\/"},"modified":"2026-03-04T10:04:13","modified_gmt":"2026-03-04T10:04:13","slug":"sloppylemming-espionage-campaign-uses-burrowshell-backdoor-and-rust-rat-to-hit-pakistan-and-bangladesh-targets","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/04\/sloppylemming-espionage-campaign-uses-burrowshell-backdoor-and-rust-rat-to-hit-pakistan-and-bangladesh-targets\/","title":{"rendered":"SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets"},"content":{"rendered":"<p>    SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and Bangladesh.<\/p>\n<p>Active since 2021 and also tracked as Outrider Tiger and Fishing Elephant, the group deployed two newly documented tools between January 2025 and January 2026: a custom backdoor called BurrowShell and a Rust-based remote access trojan equipped with keylogging capability.\u200b<\/p>\n<p>The campaign ran two separate attack paths, both launched through <a href=\"https:\/\/cybersecuritynews.com\/iranian-spear-phishing-attack\/\" id=\"112712\" target=\"_blank\" rel=\"noreferrer noopener\">spear-phishing<\/a>. The first used PDF lure documents with a blurred page and a fake \u201cDownload file\u201d button. <\/p>\n<p>Clicking it redirected victims to a ClickOnce application manifest that silently dropped a multi-stage malware chain onto their device. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjkbYFTVq8YBxH5SEr3y_GlkwmZvmSKQVteAw1tYqJaoDtFTmgJpKiNHEclm4C9hsEFNMn2XYLKrtSPx3LNfY-zTFv7mKp8fgVbOWEn80mt5MNc-3M9vlUu9vECre2mIqxwo73CqcnZI7RxF2D7S0KU2mjvdnO3_C0GUNGhcinpOhyIW2XTwU7e67e04wk\/s16000\/PDF%2520lure%2520displaying%2520blurred%2520document%2520with%2520social%2520engineering%2520message%2520%27PDF%2520reader%2520is%2520disabled%27%2520%28Source%2520-%2520Arctic%2520Wolf%29.webp?ssl=1\" alt=\"PDF lure displaying blurred document with social engineering message 'PDF reader is disabled' (Source - Arctic World)\"><figcaption class=\"wp-element-caption\">PDF lure displaying blurred document with social engineering message \u2018PDF reader is disabled\u2019 (Source \u2013 Arctic World)<\/figcaption><\/figure>\n<\/div>\n<p>The second path used macro-enabled Excel spreadsheets that, once opened, quietly downloaded and executed malicious payloads from attacker-controlled servers.\u200b<\/p>\n<p><a href=\"https:\/\/arcticwolf.com\/resources\/blog\/sloppylemming-deploys-burrowshell-and-rust-based-rat-to-target-pakistan-and-bangladesh\/\" id=\"https:\/\/arcticwolf.com\/resources\/blog\/sloppylemming-deploys-burrowshell-and-rust-based-rat-to-target-pakistan-and-bangladesh\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Arctic Wolf analysts identified both attack chains<\/a> as part of a single coordinated operation. Each relied on DLL search order hijacking to run malicious code through trusted Microsoft processes.<\/p>\n<p>By placing rogue DLLs next to legitimate, signed Microsoft binaries, the attackers executed their tools inside processes that security software typically treats as safe.\u200b<\/p>\n<p>The supporting infrastructure behind this campaign was considerable. Arctic Wolf researchers traced 112 unique Cloudflare Workers domains registered between January 2025 and January 2026 \u2014 an eight-fold increase from 13 domains documented in prior reporting.<\/p>\n<p>Each domain was named to impersonate real government entities, including the Pakistan Nuclear Regulatory Authority, Pakistan Navy, Dhaka Electric Supply Company, and Bangladesh Bank. Domain registrations peaked in July 2025, with 42 new domains added in a single month.\u200b<\/p>\n<p>Targeted sectors in Pakistan included nuclear oversight, defense logistics, telecommunications, and government administration. In Bangladesh, the group focused on energy utilities, financial institutions, and media organizations. <\/p>\n<p>This pattern aligns with intelligence-collection priorities tied to regional competition in South Asia, and the year-long campaign with expanding infrastructure signals organized, long-term intent.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"inside-the-burrowshell-infection-chain\"><strong>Inside the BurrowShell Infection Chain<\/strong><\/h2>\n<p>BurrowShell is an in-memory shellcode implant delivered through the ClickOnce attack chain. <\/p>\n<p>The infection begins when a malicious loader,\u00a0<code>mscorsvc.dll<\/code>, is pulled in by a renamed Microsoft .NET binary \u2014\u00a0<code>NGenTask.exe<\/code>, delivered as\u00a0<code>OneDrive.exe<\/code>\u00a0\u2014 placed in the same folder. Before executing any payload, the loader checks whether the parent process is running from an approved directory. <\/p>\n<p>If the check fails, the malware shuts down immediately to prevent execution inside analysis sandboxes.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhArdK9UHkA8gIdHp-ya9dBiseYfqzg5PNVC5iZQ_HELSLma0S4meoUMZi_TtY3W5dhsk7TfpkIJq1vZzhZzT7GgzX6oIurGiV5TMt05zHGUCiQNzwKGFTRqpQLtZD02-2R8nND8ObXQENGVLkm1csAdD3WGBiEPFVDa_L5dzUN-zj6JhW5UUy7NjDTCsE\/s16000\/Execution%2520chain%2520%28Source%2520-%2520Arctic%2520Wolf%29.webp?ssl=1\" alt=\"Execution chain (Source - Arctic Wolf)\"><figcaption class=\"wp-element-caption\">Execution chain (Source \u2013 Arctic Wolf)<\/figcaption><\/figure>\n<\/div>\n<p>If the location check passes, the loader writes a registry entry under\u00a0<code>SoftwareMicrosoftWindowsCurrentVersionRun<\/code>\u00a0so that\u00a0<code>OneDrive.exe<\/code>\u00a0launches on every reboot, keeping the infection persistent. <\/p>\n<p>It then reads an RC4-encrypted file called\u00a0<code>system32.dll<\/code>\u00a0and decrypts it using a hardcoded 32-character key, releasing BurrowShell into memory. Because the shellcode never lands on disk as a standalone file, file-scanning tools are far less likely to detect it.\u200b<\/p>\n<p>Once active, BurrowShell connects to its command-and-control server over port 443 and disguises its traffic as Windows Update communications. <\/p>\n<p>After registering the infected host with system details, it enters a continuous loop of heartbeat check-ins while waiting for commands. The implant supports fifteen commands \u2014 file operations, screenshot capture, shell execution, and SOCKS proxy tunneling. <\/p>\n<p>The Rust-based keylogger, deployed through the Excel macro path, extends these capabilities with keystroke recording, port scanning, and network enumeration.\u200b<\/p>\n<p>Organizations in government, defense, and critical infrastructure should take specific defensive steps. <\/p>\n<p>Email <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-security-tools\/\" id=\"11635\" target=\"_blank\" rel=\"noreferrer noopener\">security tools<\/a> should block PDF files with embedded URLs pointing to Cloudflare Workers subdomains, and macro execution in externally received Office documents should be disabled. <\/p>\n<p>Network teams should monitor connections to\u00a0<code>*.workers.dev<\/code>\u00a0domains and enable SSL\/TLS inspection for encrypted traffic to suspicious destinations. <\/p>\n<p>Endpoint rules should flag\u00a0<code>NGenTask.exe<\/code>\u00a0or\u00a0<code>phoneactivate.exe<\/code>\u00a0loading DLLs from non-standard paths and alert on unexpected\u00a0<code>CurrentVersionRun<\/code>\u00a0registry entries. <\/p>\n<p>Regular <a href=\"https:\/\/cybersecuritynews.com\/security-awareness-in-2025-why-awareness-is-more-important-than-ever\/\" id=\"119612\" target=\"_blank\" rel=\"noreferrer noopener\">security awareness<\/a> training is critical, as both attack paths depend on a victim taking a deliberate action \u2014 clicking a button or enabling macros.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/sloppylemming-espionage-campaign-uses-burrowshell-backdoor\/\">SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/sloppylemming-espionage-campaign-uses-burrowshell-backdoor\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and Bangladesh. Active since 2021 and also tracked as Outrider Tiger [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11096","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11096"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11096"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11096\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}