Overview
E2E Networks is informing customers about a cyber espionage campaign associated with the threat actor Mysterious Elephant (also known as APT-C-08, APT-K-47, and TAG-179). The group primarily targets government and public sector organizations in South Asia using phishing emails and remote access malware.
What is Happening?
Attackers are sending phishing emails containing documents that appear to be official or operational in nature. If a user opens the malicious attachment, a malware called Remcos RAT (Remote Access Trojan) is installed, allowing attackers to remotely control the infected system and steal sensitive information.
Potential Impact
A successful compromise may allow attackers to:
- Gain unauthorized access to systems.
- Steal usernames, passwords, and confidential data.
- Monitor user activity.
- Maintain long-term access to compromised machines.
- Collect sensitive government or organizational information.
Who is at Risk?
This campaign mainly targets:
- Government organizations
- Law enforcement agencies
- Defense organizations
- Public sector institutions
Organizations handling sensitive or confidential information should remain particularly vigilant.
Recommended Actions
E2E Networks recommends the following security measures:
- Do not open unexpected email attachments or links.
- Verify the authenticity of emails requesting urgent action.
- Keep operating systems and applications fully updated.
- Deploy and maintain Endpoint Detection and Response (EDR) or antivirus solutions.
- Monitor systems for unusual login activity, remote access sessions, or suspicious outbound connections.
- Conduct regular phishing awareness training for employees.

