Researchers reported a recruitment-themed malware campaign targeting Indian government job seekers with a fake Cabinet Secretariat notice for Senior Field Officer roles. The infection chain delivers a ZIP archive containing a malicious .lnk file, a PowerShell script, and a .NET executable that installs the legitimate ControlR remote management agent alongside a custom RAT called SheetAgent. The malware persists through a scheduled task or Startup-folder shortcut, disguises files with Windows-like names, and uses anti-VM, anti-sandbox, and self-cleanup checks to hinder analysis.
Seqrite said SheetAgent uses hardcoded Google service account credentials to access Google Sheets and Google Drive, with an attacker-controlled sheet acting as a backup command-and-control and exfiltration channel. Investigators also linked infrastructure at 38.242.157.89 to the decoy PDF and several authenticated management panels, including SecureMonitor and PrivateRat. The tradecraft overlaps with earlier campaigns that used cloud services such as Google Sheets, Firebase, GitHub, and Microsoft Graph for covert C2 against Indian targets, and Seqrite attributed the operation to APT36 with medium confidence.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Seqrite documented a recruitment-themed malware campaign targeting Indian government job seekers with a fake Cabinet Secretariat notice, using a ZIP-delivered LNK, PowerShell, and .NET payload chain to install ControlR and the custom SheetAgent RAT. The report also identified infrastructure at 38.242.157.89 and attributed the activity to APT36 with medium confidence based on targeting and tradecraft similarities.
ThreatLabz described an active campaign targeting Windows systems in India that used PDF lures and later malicious LNK files to deliver the SHEETCREEP and FIREPOWER backdoors. The report also documented use of Google Sheets, Firebase, GitHub, and Microsoft Graph/Azure-based cloud services for command-and-control and exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceseqrite.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.