SloppyLemming

Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:17:42

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:pk country_code:lk country_code:bd country_code:cn

Context

SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, malware delivery and command and control (C2). This actor conducts extensive operations targeting Pakistani, Sri Lanka, Bangladesh, and China. Industries targeted include government, law enforcement, energy, telecommunications, and technology entitie

Detection coverage

  • 4 YARA rules

Malware & tools used

Related threat objects

Reports & references

  • blog.cloudflare.com — Unraveling Sloppylemming Operations (report)

External references