Fishing Elephant targets government and diplomatic entities using AresRAT via legitimate platforms.
Analyst brief
Fishing Elephant (also known as Outrider Tiger) is a threat actor primarily targeting government and diplomatic entities. They rely on consistent TTPs, using AresRAT delivered through legitimate platforms such as Heroku and Dropbox. Defenders should focus on detecting executables hidden within certificate files, geo-fencing techniques, and anomalous network traffic patterns.
Fishing Elephant
Outrider Tiger
unknown
Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan. They rely on consistent TTPs, including payload and communication patterns, while occasionally incorporating new techniques such as geo-fencing and hiding executables within certificate files. Their tool of choice is AresRAT, which they deliver through platforms like Heroku and Dropbox. Recently, they have shifted their focus to government and diplomatic entities in Turkey, Pakistan, Bangladesh, Ukraine, and China.