A threat actor, known as SloppyLemming, likely operating out of India, is relying on various cloud to carry out cyberattacks against energy, defense, government, telecommunications, and technology entities in Pakistan, according to Cloudflare.
See also: CMS reports 3.1 million data breach

The SloppyLemming group 's activities align with Outrider Tiger , a threat actor that CrowdStrike had previously linked to India and which is known for using adversary emulation frameworks such as Sliver and Cobalt Strike in its attacks .
Since 2022, the hacking group SloppyLemming has been observed relying on Cloudflare Workers for espionage campaigns targeting Pakistan and other South and East Asian countries, including Bangladesh, China, Nepal, and Sri Lanka. Cloudflare has identified 13 workers associated with the threat actor.
According to Cloudflare, it appears that the group is particularly interested in compromising Pakistani police departments and other law enforcement agencies, and possibly targeting entities associated with Pakistan's only nuclear power facility.
See also: Cyberattack causes MoneyGram service outage
Using phishing emails, the threat actor delivers malicious links to its victims, relying on a custom tool called CloudPhish to create a malicious Cloudflare Worker to collect and extract credentials, and uses scripts to collect emails of interest from victims' accounts.

In some attacks, SloppyLemming would also attempt to harvest Google OAuth tokens, which are delivered to the malicious actor via Discord. Malicious PDF files and Cloudflare Workers were believed to be used as part of the attack chain.
SloppyLemming has also been observed delivering spear-phishing emails as part of an attack chain based on code hosted on a GitHub repository controlled by the attackers to check when the victim accesses the phishing. The malware delivered as part of these attacks communicates with a Cloudflare Worker that relays requests to the attackers’ command and control (C&C) server.
See also: Deloitte denies user data is at risk after breach
Cyberattacks, such as those by the SloppyLemming group against Pakistan, are a significant threat in our digital age, as they can target individuals as well as large corporations. These attacks often involve attempting to access sensitive information or compromise electronic systems, causing serious financial and moral damage. The types of cyberattacks vary, including malware, phishing, ransomware , and DDoS attacks. Protecting against cyberattacks requires continuous efforts and the adoption of effective security practices, such as using strong passwords, regular security updates, and educating users to recognize threats.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
