“Gopher Strike”: New Pakistan-Linked Cyber Campaigns Target Indian Government
ID: 55f06862-88aa-5678-80c1-20c016c8d6b3
STIX ID: report--55f06862-88aa-5678-80c1-20c016c8d6b3
Feed Name: securityonline.info
Zscaler ThreatLabz reported two Pakistan-linked cyberespionage campaigns (Gopher Strike and Sheet Attack) observed from September 2025 targeting Indian government entities. Gopher Strike uses Golang-based tools—GOGITTER (downloader), GOSHELL (shellcode loader for Cobalt Strike Beacon), and GITSHELLPAD (backdoor abusing private GitHub repos for C2)—delivered via malicious PDFs and ISO payloads; Sheet Attack reportedly experiments with generative AI in malware. Researchers see similarities to APT36 but suggest a possible new subgroup, and advise monitoring PDFs/ISO attachments and traffic to private GitHub repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
