securityonline.info 7/20/2026, 8:20:40 AM · external

SheetAgent RAT hits Indian job seekers via fake govt zip

SheetAgent RAT hits Indian job seekers via fake govt zip
CyberSIXT Evidence Panel
Primary Source seqrite.com
Threat Actor

OPERATION ShadowRecruit is a multi-stage malware campaign uncovered by Seqrite's APT Research Team, targeting Indian job seekers with a recruitment lure. The campaign uses a ZIP archive disguised as an Indian government job hiring notice, which installs a custom remote access trojan (RAT) called SheetAgent alongside the legitimate ControlR management tool. The malware communicates with the attacker via a Google Sheets document, obfuscating its activities by blending into regular Google API traffic.

Victims are primarily from government, education, and technology sectors, with no specific victim count reported. Seqrite attributes the campaign to the suspected APT36 group, linked to previous attacks on Indian government targets. Recommendations for protection include being cautious of unsolicited recruitment files and monitoring for unexpected installations of remote management tools.

View Primary Source Via securityonline.info

Article by CyberSIXT