Outrider Tiger is an India-linked cyber-espionage threat cluster associated by researchers with Sloppy Lemming and connected in some reporting to Fishing Elephant. The actor has targeted organizations in South Asia, with a particular focus on Pakistan and Bangladesh, including nuclear-regulatory entities, defense firms, critical infrastructure, logistics providers, and telecommunications organizations. Activity attributed to this cluster reflects a regional espionage mission set centered on intelligence collection against strategic, governmental, and security-relevant targets. The group relies heavily on phishing-based intrusion chains and credential-focused collection rather than public reporting of zero-day-driven edge-device exploitation. Observed delivery methods include PDF lures that redirect victims and macro-enabled Excel documents used to deploy a Rust-based keylogger. Reporting also links the actor to credential theft and broader post-compromise collection activity. Over time, the cluster has evolved from use of common red-team frameworks such as Cobalt Strike and Havoc toward custom tooling written in Rust, indicating increasing malware-development maturity. Outrider Tiger has also expanded its use of cloud and serverless command-and-control infrastructure, including Cloudflare Workers, reflecting an effort to improve scalability, anonymity, and defense evasion. At the same time, the actor has been noted for operational security weaknesses, including exposed infrastructure directories, suggesting uneven tradecraft despite growing sophistication. Broader overlap has been noted between this cluster and other India-aligned activity sets, especially Bitter, but distinct India-nexus groups such as Dropping Elephant and Mysterious Elephant are tracked separately.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.