logo

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers

ID: 615a5a4a-8f7f-5358-be14-53131997888e

STIX ID: report--615a5a4a-8f7f-5358-be14-53131997888e

Feed Name: Seqrite Blog

Threat Score
78/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Priya Patel

...
...

Operation ShadowRecruit is a multi-stage targeted malware campaign that lures Indian government job applicants with a fake recruitment document delivered in a ZIP archive; the chain uses a malicious LNK that runs a Base64 PowerShell downloader to install a legitimate ControlR agent and execute a .NET dropper which persists via scheduled tasks or startup shortcuts and deploys SheetAgent RAT that uses embedded Google service account credentials to use Google Sheets/Drive as a backup C2. The report includes full technical analysis, IOCs (hashes, IP 38.242.157.89, URLs), MITRE ATT&CK mapping, and attributes the activity to APT36 with moderate confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.