Fishing Elephant is an India-linked cyber-espionage threat actor associated by some researchers with the cluster also tracked as Sloppy Lemming and Outrider Tiger. The group has targeted organizations in South Asia, particularly in Bangladesh and Pakistan, with an emphasis on nuclear-related entities, defense organizations, logistics, telecommunications providers, and other critical infrastructure. Its activity fits a regional intelligence-collection mission rather than financially motivated crime. The actor is known for phishing-led intrusion activity and credential-focused operations. Reported delivery chains include lure documents such as PDFs that redirect victims and macro-enabled Microsoft Excel files that deploy malware, including AresRAT and a Rust-based keylogger. Researchers have also linked the group to broader use of custom Rust tooling and cloud-hosted command-and-control infrastructure, including serverless platforms, reflecting an evolution from reliance on commodity red-team frameworks toward more tailored malware and operational infrastructure. Fishing Elephant’s observed tradecraft includes initial access through social engineering, credential theft, keylogging, persistence, post-compromise command-and-control, and data collection consistent with espionage objectives. Reporting also notes operational overlap or partial clustering with other India-aligned activity, but Fishing Elephant should be distinguished from separate India-nexus groups such as Dropping Elephant and Mysterious Elephant unless specific evidence supports convergence in a given campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
India-nexus cyber-espionage group reported as linked/overlapping with Sloppy Lemming; described as focusing on nuclear, defense, logistics, and telecommunications providers.
Continued regional targeting with consistent TTPs; observed adoption of a new keylogger while maintaining established payload/communications patterns.
Uses cloud platforms (Heroku, Dropbox) to deliver AresRAT; added geo-fencing and hiding executables within certificate files to hinder analysis; targets government and diplomatic entities across multiple countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.