Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Hackers With Bad OPSEC Are Targeting Pakistan, Sri Lanka, and China
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Hackers With Bad OPSEC Are Targeting Pakistan, Sri Lanka, and China
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Security » Hackers With Bad OPSEC Are Targeting Pakistan, Sri Lanka, and China

Security

Hackers With Bad OPSEC Are Targeting Pakistan, Sri Lanka, and China

SloppyLemming hackers target South Asia, exposing government entities to attacks through cloud service exploits.

Marco Rizal
Last updated: September 27, 2024 10:57 am
By Marco Rizal - Editor, Journalist 3 Min Read
Share
Hackers With Bad OPSEC Are Targeting Pakistan Sri Lanka and China
SHARE
  • SloppyLemming hackers target Pakistan, Sri Lanka, Bangladesh, and China.
  • Their poor operational security makes tracking them easy for investigators.
  • SloppyLemming uses cloud services for phishing, malware, and C2.

Cloudforce One discovered a not-so-slick operation by the hacker group SloppyLemming, which appears to be operating with more enthusiasm than skill.

These cybercriminals are hacking their way into South and East Asia with the ease of a bull in a china shop.

They've targeted critical sectors—government, energy, and telecommunications in countries such as Pakistan, Sri Lanka, Bangladesh, and China, using basic tools like Cobalt Strike and some assistance from popular cloud services.

Between late 2022 and now, SloppyLemming has thrown its digital weight around, primarily targeting Pakistan's government and law enforcement agencies.

image 95
Phishing webpage used by SloppyLemming (Credit: Cloudforce One)

Cloudforce One had a front-row seat to the group's espionage activities due to their lack of operational security (OPSEC), which was similar to watching a poorly executed magic trick with all the wires and mirrors exposed.

Cloudforce One person discovered that SloppyLemming's favorite trick is credential harvesting, and their phishing emails are as predictable as they come.

Their go-to email? A bogus IT department message threatens to suspend accounts unless users immediately update their credentials.

When an unsuspecting user falls for it, they're redirected to a fake portal where SloppyLemming collects login information.

In a particularly clumsy move, SloppyLemming employs a custom tool called “CloudPhish” to trick Cloudflare Workers into logging credentials and sending them directly to the group's Discord channel.

Yes, they use Discord, demonstrating yet again that they may not be the most professional around.

These amateurs also experiment with malware delivery, as evidenced by a recent July 2024 example in which they distributed a malware-laden RAR file named after a popular scanner app.

It's as if they're aiming for obvious phishing attempt of the year.

Despite targeting critical infrastructure such as police departments and nuclear facilities, SloppyLemming is unable to cover their tracks, allowing Cloudforce One to easily expose their malware operations.

Even as they broaden their efforts, hinting at potential government targeting in Australia, their reliance on cloud services such as Cloudflare, Dropbox, and Discord makes their actions easier to track.

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Grayscale Dogecoin ETF Makes Historic NYSE Trading Debut

November 24, 2025

Breaking: FBI Probes Cardano Network Split After Malicious Transaction

November 24, 2025

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

You might also like

Bitcoins DoS Vulnerability

Bitcoin’s DoS Vulnerability Lets Hackers Crash Miners For Less Than 1% of a Block

Kaspersky Forces Users to UltraAV After U.S. Ban Is This the Right Move

Kaspersky Forces Users to UltraAV After U.S. Ban, Is This the Right Move?

Hackers Are Buying Big YouTube Channels to Infect You with Malware

Hackers Are Buying Big YouTube Channels to Infect You with Malware

Russian Linked Crypto Scammers Are Targeting The 2024 US Election

Russian-Linked Crypto Scammers Are Targeting The 2024 US Election

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?