# Seqrite uncovers ShadowRecruit malware targeting Indian job seekers

2026-08-20T01:46:06+00:00 | Technology | Indian Opinion Desk

Corroboration: 1 independent outlet

Seqrite, the enterprise security arm of Quick Heal Technologies, has revealed a malware campaign called Operation ShadowRecruit that targets Indian government job seekers. The attackers use a fake recruitment notice for Senior Field Officer positions in the Cabinet Secretariat, delivered via a ZIP archive containing a malicious LNK file, a PowerShell script, and a.NET executable. The malware deploys a custom remote access trojan named SheetAgent RAT, which uses Google Sheets as a backup command-and-control channel after initially abusing the legitimate ControlR remote management platform. The campaign begins with a ZIP archive that appears to contain 'approved documents' but includes a disguised shortcut, a PowerShell downloader, and a hidden executable. The decoy document imitates an official recruitment notice with details such as eligibility criteria, vacancies, and deadlines, keeping the victim focused while the malware executes in the background. The final payload registers infected systems in a spreadsheet, reads commands from attacker-controlled cells, and writes results back, ensuring resilience even if one channel is disrupted. The campaign affects government, education, and technology-oriented users in India. Seqrite's analysis shows the malware includes anti-analysis checks and cleanup routines to evade sandboxes. The threat aligns with trends in Seqrite's India Cyber Threat Report 2026, which documented a shift toward stealthier, automation-assisted attacks using cloud and collaboration platforms.

## Indian Opinion Analysis

Job recruitment lures remain among the most effective social engineering tactics in India because they exploit the urgency and trust of lakhs of applicants competing for limited government posts. The use of Google Sheets as a command-and-control channel is notable: it hides malicious traffic inside legitimate cloud traffic, making detection harder for traditional network monitors. The Cabinet Secretariat lure is particularly potent given the sensitivity of the organisation. Organisations handling applicant data should enforce strict verification of recruitment notices, and employees should independently verify job postings on official government websites. The next indicator to watch is whether similar campaigns using other government bodies as lures appear in the coming months.

## Coverage

- itvoice.in <https://www.itvoice.in/seqrite-uncovers-operation-shadowrecruit-fake-recruitment-campaign-targets-indian-job-seekers-with-multi-stage-malware>
  Reports the findings factually without taking a side, framing the threat as a security alert rather than a government failure.

This story was synthesised by AI from the source linked above.

Tags: India, Quick Heal Technologies, Seqrite
Canonical: https://indianopinion.org/seqrite-uncovers-shadowrecruit-malware-targeting-indian-job-seekers/
License: Summary and commentary (c) Indian Opinion, reusable with attribution. Facts belong to the linked sources.
Cite: https://indianopinion.org/seqrite-uncovers-shadowrecruit-malware-targeting-indian-job-seekers/#story-in-brief

Review state: restored archive article, accurate at time of publication, not offered to search indexes.

How this brief was made: an AI model read the report linked above and wrote this summary and analysis, which were published automatically. Published briefs are sampled every hour by an automated quality check; the editor verifies its findings and approves corrections, and corrected briefs carry a dated correction line. We do no original reporting. Methodology: https://indianopinion.org/ai-use-policy/
