logo

VICEROY_TIGER__2019__LUCKY_ELEPHANT_Campaign_Masquerading.pdf

ID: de16a0f6-eb7b-4d57-96a2-2457a9fe7b0d

STIX ID: report--de16a0f6-eb7b-4d57-96a2-2457a9fe7b0d

Threat Score

68/100

Uploaded: 2026-08-19

Published Date: 2019-03-28

Last Modified Date: 2019-03-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASERT researchers analyze the LUCKY ELEPHANT credential harvesting campaign that uses doppelganger webpages to harvest login credentials by impersonating government, telecommunications, and military entities in South Asia. The operation is primarily credential theft via phishing with no observed malware payloads; infrastructure includes a small set of IPs and domains, some tied to Indian and Chinese APT activity, and targets governments in the region with recommendations to monitor IOCs and enforce MFA.