SYMBOLCOMMON_NAMEaka. SYNONYMS

Mysterious Elephant  (Back to overview)


Mysterious Elephant is an APT group active since 2023 that primarily targets government and foreign affairs entities across South Asia, especially Pakistan, Bangladesh, Sri Lanka, Nepal, and Afghanistan. In its early-2025 campaign it shifted toward spear-phishing and custom/customized tools—including the BabShell reverse shell and MemLoader HidenDesk/Edge loaders—to deploy RATs like Remcos and VRat, while also using WhatsApp-specific exfiltration tools to steal shared documents, images, and archives. The group shares code and infrastructure with other APT clusters (Origami Elephant, Confucius, SideWinder), reflecting ongoing tool reuse and collaboration among South Asian threat actors.


Associated Families

There are currently no families associated with this actor.


References
2025-10-21AnomaliAnomali Cyber Watch
Anomali Cyber Watch: F5 Breach, Mysterious Elephant APT, Malicious MCP Servers, and More
MonsterV2 Mysterious Elephant
2025-10-15KasperskyNoushin Shabab, Ye Jin
Mysterious Elephant: a growing threat
Remcos Mysterious Elephant

Credits: MISP Project