logo

Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants

ID: 32213e62-1dd2-56cc-8191-834fee0e0885

STIX ID: report--32213e62-1dd2-56cc-8191-834fee0e0885

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Varshini

...
...

Researchers describe 'Operation ShadowRecruit', a multi-stage campaign targeting Indian government job applicants using a ZIP lure containing an LNK that executes a PowerShell script to install a legitimate RMM (ControlR) with attacker-controlled enrollment and then a .NET dropper that deploys a custom RAT; the malware includes extensive anti-analysis checks and researchers observed multiple C2 management panels and provided IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.