Security researchers reported Pakistan-linked threat activity targeting Indian government entities in campaigns dubbed Gopher Strike and Sheet Attack, assessed with medium confidence to potentially originate from a new subgroup or a parallel Pakistan-based actor rather than being definitively attributable to APT36. Sheet Attack uses legitimate services including Google Sheets, Firebase, and email for command-and-control (C2), while Gopher Strike begins with phishing emails delivering deceptive PDFs that display blurred content and a fake prompt to install an Adobe Acrobat Reader DC update.
In Gopher Strike, clicking the “Download and Install” lure triggers delivery of an ISO payload only when server-side checks confirm the victim is in India and using a Windows user agent, a tactic intended to evade automated analysis. The ISO contains a Golang downloader, GOGITTER, which creates a VBScript (e.g., windows_api.vbs) in common directories (including C:\Users\Public\Downloads, C:\Users\Public\Pictures, and %APPDATA%) to poll for instructions and retrieve additional payloads, including GITSHELLPAD, which is described as leveraging private GitHub repositories (with embedded authentication tokens) for staging/persistence and follow-on access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz disclosed the two campaigns publicly, detailing their targeting of Indian government entities and their abuse of legitimate services such as GitHub, Google Sheets, and Firebase for command-and-control. The report also noted that Sheet Attack was less fully described but involved distinct tradecraft from Gopher Strike.
After the ISO was executed, the attackers deployed custom Golang tools including GOGITTER as a downloader, GITSHELLPAD as a GitHub-based backdoor, and GOSHELL as a loader. The malware established persistence, polled private GitHub repositories for tasking, and ultimately loaded Cobalt Strike Beacon while using evasion techniques such as hostname checks and file-size inflation.
In the Gopher Strike intrusion chain, victims received phishing emails with PDF lures impersonating government communications that displayed a fake Adobe Acrobat Reader DC update prompt. The prompt led targets in India using Windows systems to download a malicious ISO, helping the attackers narrow deployment and evade analysis.
Zscaler ThreatLabz first detected two previously undocumented campaigns, Gopher Strike and Sheet Attack, in September 2025 targeting Indian government entities. The activity was assessed with medium confidence as Pakistan-linked and showed some similarities to APT36 while possibly representing a new subgroup or parallel actor.
Open-source reporting describes sustained Pakistan-linked cyber-espionage activity during 2024 into 2025 against Indian government, defense, and academic organizations. The operations used spear-phishing, LNK and ISO payloads, Golang malware, cloud-based command-and-control, and in some cases Android spyware such as CapraRAT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcerescana.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.