Threat intelligence report · AlienVault OTX

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers

A sophisticated cyber campaign targets Indian government job seekers using fake recruitment advertisements for Senior Field Officer positions in the Cabinet Secretariat. The attack chain begins with a malicious ZIP archive containing a disguised LNK file, PowerShell script, and .NET executable. Attackers abuse the legitimate ControlR remote management tool for persistent access and deploy SheetAgent RAT, a custom .NET malware that uses Google Sheets as a command-and-control channel. The malware employs multiple persistence mechanisms including scheduled tasks and startup folder entries, while incorporating extensive anti-analysis checks to detect virtualized environments. Infrastructure analysis reveals multiple web-based management panels and connections to APT36 based on targeting patterns and tradecraft similarities.

· unknown severity · unattributed attribution

Evidence and provenance

Original source
AlienVault OTX report ↗
Published
2026-07-14T16:17:26.318000Z
Confidence basis
No actor match
Record ID
bab5010336cad590dcfe

Affected sectors

government

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.