Researchers reported a recruitment-themed malware campaign targeting Indian government job seekers with a fake Cabinet Secretariat notice for Senior Field Officer roles. The infection chain delivers a ZIP archive containing a malicious .lnk file, a PowerShell script, and a .NET executable that installs the legitimate ControlR remote management agent alongside a custom RAT called SheetAgent. The malware persists through a scheduled task or Startup-folder shortcut, disguises files with Windows-like names, and uses anti-VM, anti-sandbox, and self-cleanup checks to hinder analysis.
Seqrite said SheetAgent uses hardcoded Google service account credentials to access Google Sheets and Google Drive, with an attacker-controlled sheet acting as a backup command-and-control and exfiltration channel. Investigators also linked infrastructure at 38.242.157.89 to the decoy PDF and several authenticated management panels, including SecureMonitor and PrivateRat. The tradecraft overlaps with earlier campaigns that used cloud services such as Google Sheets, Firebase, GitHub, and Microsoft Graph for covert C2 against Indian targets, and Seqrite attributed the operation to APT36 with medium confidence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Seqrite documented a recruitment-themed malware campaign targeting Indian government job seekers with a fake Cabinet Secretariat notice, using a ZIP-delivered LNK, PowerShell, and .NET payload chain to install ControlR and the custom SheetAgent RAT. The report also identified infrastructure at 38.242.157.89 and attributed the activity to APT36 with medium confidence based on targeting and tradecraft similarities.
ThreatLabz described an active campaign targeting Windows systems in India that used PDF lures and later malicious LNK files to deliver the SHEETCREEP and FIREPOWER backdoors. The report also documented use of Google Sheets, Firebase, GitHub, and Microsoft Graph/Azure-based cloud services for command-and-control and exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceseqrite.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.