Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers
ID: 615a5a4a-8f7f-5358-be14-53131997888e
STIX ID: report--615a5a4a-8f7f-5358-be14-53131997888e
Feed Name: Seqrite Blog
Operation ShadowRecruit is a multi-stage targeted malware campaign that lures Indian government job applicants with a fake recruitment document delivered in a ZIP archive; the chain uses a malicious LNK that runs a Base64 PowerShell downloader to install a legitimate ControlR agent and execute a .NET dropper which persists via scheduled tasks or startup shortcuts and deploys SheetAgent RAT that uses embedded Google service account credentials to use Google Sheets/Drive as a backup C2. The report includes full technical analysis, IOCs (hashes, IP 38.242.157.89, URLs), MITRE ATT&CK mapping, and attributes the activity to APT36 with moderate confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
