
A fake recruitment campaign named Operation ShadowRecruit is targeting Indian job seekers with multi-stage malware, cybersecurity firm Seqrite has found. The campaign uses a ZIP archive disguised as approved documents for Senior…
A fake recruitment campaign named Operation ShadowRecruit is targeting Indian job seekers with multi-stage malware, cybersecurity firm Seqrite has found. The campaign uses a ZIP archive disguised as approved documents for Senior Field Officer posts in the Cabinet Secretariat. It contains a malicious LNK file, a PowerShell script and a.NET executable that deploy a remote access trojan called SheetAgent RAT.

The attackers abuse the legitimate ControlR remote management platform and use Google Sheets as a backup command-and-control channel. The malware registers infected systems in a spreadsheet, reads commands from attacker-controlled cells and writes results back. A decoy recruitment document with eligibility criteria and deadlines distracts the victim while the malware executes in the background. The campaign has affected government, education and technology-oriented users in India.
The attack exploits a predictable weakness: trust in official-looking recruitment notices for coveted government jobs. Seqrite's findings show the malware includes anti-analysis checks and cleanup routines to evade detection, a hallmark of professionally developed cyberweapons. The use of Google Sheets as a command channel is notable because traffic to Google domains blends with legitimate corporate traffic, bypassing many network filters. Organisations handling applicant data face both credential theft and exposure risk under the DPDP Act, which mandates data protection safeguards. The Cabinet Secretariat recruitment theme suggests attackers researched current government hiring patterns to maximise the lure's credibility.
Source: cxotoday.com
This story was synthesised by AI from the source linked above.