Arctic Wolf Labs has documented a year-long cyber espionage campaign attributed with moderate confidence to SloppyLemming (also known as Outrider Tiger/Fishing Elephant), a suspected India-aligned threat actor. The campaign targeted government, defense, nuclear, energy, and telecom sectors in Pakistan and Bangladesh using two attack chains: PDF lures triggering ClickOnce manifests that deploy a custom x64 shellcode backdoor called BurrowShell via DLL sideloading, and macro-laden Excel files delivering a Rust-based keylogger. BurrowShell supports 15 commands including file operations, screenshots, shell execution, and SOCKS proxy tunneling, masquerading C2 traffic as Windows Update communications. The Rust keylogger adds port scanning and network enumeration. Infrastructure analysis identified 112 Cloudflare Workers domains impersonating Pakistani and Bangladeshi government entities, an 8x expansion from prior reporting. Three domains had open directory misconfigurations exposing malware components including Havoc C2 framework artifacts. Peak infrastructure registration occurred in July 2025 with 42 new domains. The report includes full IOCs, detection recommendations, and mitigation guidance.