SloppyLemming BurrowShell and Rust-based keylogger activity
Malware Activity
Summary
Hide ▲
Show ▼
SloppyLemming deployed BurrowShell and a Rust-based keylogger through two attack chains, expanding its malware toolkit for backdoor access, credential theft, and reconnaissance against targeted systems in Pakistan and Bangladesh. The activity ran from January 2025 to January 2026 and used spear-phishing with PDF lures and macro-enabled Excel documents to start the infection chains. The malware and delivery flow show a shift toward Rust-based tooling and layered staging.
Related Happenings
Webworm EchoCreep and GraphWorm backdoor expansion
Malware Activity
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
**Webworm** expanded its malware arsenal in **2025** with the custom backdoors **EchoCreep** and **GraphWorm**, increasing its ability to run stealthy **command-and-control** oper...
Webworm EchoCreep and GraphWorm backdoor expansion
Malware ActivityAbout this happening: **Webworm** expanded its malware arsenal in **2025** with the custom backdoors **EchoCreep** and **GraphWorm**, increasing its ability to run stealthy **command-and-control** oper...
Beagle backdoor distributed via fake Claude site and DLL sideloading
Malware Activity
First: 07.05.2026 16:15
Last: 07.05.2026 16:15
Sources 1
About this happening:
The **Beagle** backdoor is now being distributed through a **fake Claude website**, putting **Windows users** at risk of infection through a **DLL sideloading chain**. The lure de...
Beagle backdoor distributed via fake Claude site and DLL sideloading
Malware ActivityAbout this happening: The **Beagle** backdoor is now being distributed through a **fake Claude website**, putting **Windows users** at risk of infection through a **DLL sideloading chain**. The lure de...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
Campaign
First: 06.05.2026 16:02
Last: 06.05.2026 16:02
Sources 1
About this happening:
The **MuddyWater** campaign used **Microsoft Teams** social engineering and a **Chaos ransomware** decoy to gain access, steal credentials, and establish persistence. The operatio...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
CampaignAbout this happening: The **MuddyWater** campaign used **Microsoft Teams** social engineering and a **Chaos ransomware** decoy to gain access, steal credentials, and establish persistence. The operatio...
Ministry of Justice and Legal Affairs of Oman hit by network compromise
Incident
First: 06.05.2026 16:00
Last: 06.05.2026 16:00
Sources 1
About this happening:
The **Ministry of Justice and Legal Affairs of Oman** suffered an **active intrusion** that exposed **session logs** and **more than 26,000 user records**, raising risk to judicia...
Ministry of Justice and Legal Affairs of Oman hit by network compromise
IncidentAbout this happening: The **Ministry of Justice and Legal Affairs of Oman** suffered an **active intrusion** that exposed **session logs** and **more than 26,000 user records**, raising risk to judicia...
ABCDoor backdoor activity in Silver Fox attacks
Malware Activity
First: 04.05.2026 14:35
Last: 04.05.2026 14:35
Sources 1
About this happening:
The newly identified **ABCDoor** backdoor is being used in **real-world attacks** by **Silver Fox**, expanding the group's malware set and increasing the risk of covert remote acc...
ABCDoor backdoor activity in Silver Fox attacks
Malware ActivityAbout this happening: The newly identified **ABCDoor** backdoor is being used in **real-world attacks** by **Silver Fox**, expanding the group's malware set and increasing the risk of covert remote acc...
Timeline
-
03.03.2026 08:53 2 articles · 2mo ago
SloppyLemming dual-chain malware activity in Pakistan and Bangladesh
Initial DisclosureArctic Wolf attributed SloppyLemming to attacks on government entities and critical infrastructure operators in Pakistan and Bangladesh, describing two attack chains that used spear-phishing PDF lures and macro-enabled Excel documents to deliver BurrowShell and a Rust-based keylogger. The delivery flow used ClickOnce application manifests, NGenTask.exe, and mscorsvc.dll for DLL side-loading, while BurrowShell provided file system manipulation, screenshot capture, remote shell execution, and SOCKS proxy tunneling with RC4-encrypted command-and-control traffic that mimicked Windows Update service communications. Investigators also identified 112 Cloudflare Workers domains registered during the one-year period, reflecting a larger infrastructure footprint tied to the campaign.
Show sources
- SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains — thehackernews.com — 03.03.2026 08:53
- Indian APT 'Sloppy Lemming' Targets Defense, Critical Infrastructure — www.darkreading.com — 04.03.2026 00:24