SloppyLemming Operations Target Entities Across South Asia

"Between late 2022 and 2024 the threat actor the threat actor identified as SloppyLemming (aka Fishing Elephant) has targeted various South and East Asian countries such as Pakistan using cloud service providers for credential harvesting malware delivery and C2 infrastructure. They target government defense telecommunications and energy sectors and had been seen extending their reach beyond Pakistan to include Bangladesh Sri Lanka and China. The phishing campaigns utilize the custom-built tool CloudPhish and focuses on stealing credentials and emails.