VICEROY_TIGER__2019__LUCKY_ELEPHANT_Campaign_Masquerading.pdf
ID: de16a0f6-eb7b-4d57-96a2-2457a9fe7b0d
STIX ID: report--de16a0f6-eb7b-4d57-96a2-2457a9fe7b0d
Threat Score
68/100
Uploaded: 2026-08-19
Published Date: 2019-03-28
Last Modified Date: 2019-03-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASERT researchers analyze the LUCKY ELEPHANT credential harvesting campaign that uses doppelganger webpages to harvest login credentials by impersonating government, telecommunications, and military entities in South Asia. The operation is primarily credential theft via phishing with no observed malware payloads; infrastructure includes a small set of IPs and domains, some tied to Indian and Chinese APT activity, and targets governments in the region with recommendations to monitor IOCs and enforce MFA.
