Mysterious Elephant — APT Profile

Mysterious Elephant is a South Asia-focused espionage actor that Kaspersky has tracked since 2023 and that Knownsec 404 tracks as APT-K-47. Its primary targets are government entities and foreign affairs sectors, with victims concentrated in Pakistan, Bangladesh, Afghanistan, Nepal and Sri Lanka, and a marked interest in diplomatic institutions reflected in its spear-phishing lures. Its early intrusions resembled those of the Confucius threat actor, but Kaspersky's further analysis revealed a more complex picture: the group's malware contains code from Origami Elephant, Confucius and SideWinder, which Kaspersky reads as deep collaboration and resource sharing between teams rather than a shared identity, noting that the borrowed tooling had already been abandoned or replaced by its original developers. Because no vendor has publicly attributed the group to a sponsoring state, its origin is carried here as Unknown.

Also tracked as

APT-K-47

Countries linked to this actor

Read the full analysis on IntelFusions