Origami Elephant is an espionage-focused threat actor associated with activity targeting South Asia, particularly Pakistan and Afghanistan. The group has been linked to malware development and tooling that overlaps with other regional intrusion sets. Known tooling associated with Origami Elephant includes the downloader Vtyrei and related variants, as well as a .NET-based backdoor referred to as Firebird. Reporting has also noted code overlap or reuse involving Origami Elephant malware and tooling later observed in other clusters, indicating either shared development lineage, code borrowing, or reuse across adjacent threat ecosystems. Origami Elephant has been connected to campaigns against government and foreign-policy-related targets. Its tradecraft includes malware staging and backdoor deployment in support of cyber-espionage objectives. The actor is also notable for having tooling or code artifacts referenced in later investigations of other South Asia-focused activity, where malware contained components associated with Origami Elephant alongside code from other APT groups. Publicly available facts in this context do not support a high-confidence attribution to a specific state, nor do they establish ransomware or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT whose tooling/code (including the Vtyrei downloader) was historically used by Origami Elephant and later adopted/maintained by Mysterious Elephant.
Cluster associated with downloader/backdoor development and limited targeting in Pakistan and Afghanistan; includes CSVtyrei downloader and Firebird .NET backdoor protected with ConfuserEx.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.