SloppyLemming
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:17:42
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:pk country_code:lk country_code:bd country_code:cn
Context
SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, malware delivery and command and control (C2). This actor conducts extensive operations targeting Pakistani, Sri Lanka, Bangladesh, and China. Industries targeted include government, law enforcement, energy, telecommunications, and technology entitie
Detection coverage
- 4 YARA rules
Malware & tools used
- Havoc (malware)
Related threat objects
- Fishing Elephant (threat-actor)
Reports & references
- blog.cloudflare.com — Unraveling Sloppylemming Operations (report)