Mumbai, 24 August 2026: Seqrite, the enterprise security arm of Quick Heal Technologies Limited, has uncovered a malware campaign targeting Indian job seekers through a fake government recruitment notice. The campaign, named Operation ShadowRecruit, uses a false recruitment notice for Senior Field Officer positions in the Cabinet Secretariat to trick victims into opening a malicious ZIP archive.

Researchers at Seqrite Labs found that the campaign uses several stages to infect targeted devices. The attack combines a malicious shortcut, PowerShell activity and a .NET executable to establish access and maintain control over infected systems.

Fake Recruitment Notice Lures Victims

The campaign begins with a ZIP archive that appears to contain approved recruitment documents. However, the archive contains a malicious LNK file, a PowerShell script and a hidden .NET executable.

The attackers designed the lure around government recruitment. This makes the campaign more convincing for people actively searching for public-sector jobs. The fake notice includes details such as eligibility criteria, vacancies, application instructions and deadlines.

These details make the document look like a genuine recruitment notice. The victim therefore has a clear reason to open the attached files.

Malicious LNK Starts the Infection

The attack moves to its next stage when the victim opens the malicious LNK file. The shortcut uses a browser icon to appear less suspicious. It then launches a PowerShell command in hidden mode.

The PowerShell stage downloads and enrols the victim’s computer into ControlR, a legitimate remote management platform. The attackers then use this access to continue the infection and trigger the .NET dropper.

The dropper creates persistence on the infected system. It can use a scheduled task or a startup shortcut to ensure that the malicious activity continues after a system restart.

At the same time, the campaign displays a decoy recruitment document on the victim’s screen. This keeps the victim focused on the fake job opportunity while the malware continues working in the background.

SheetAgent RAT Uses Google Sheets

Seqrite found another notable part of Operation ShadowRecruit. The attackers use Google Sheets as a backup command-and-control channel for the final payload.

Seqrite named the malware SheetAgent RAT. The malware uses hardcoded Google service account credentials to access Google Sheets and Google Drive APIs.

SheetAgent RAT can register infected systems in a spreadsheet. It can also read commands from attacker-controlled cells and write the results back to the same environment.

This approach gives the attackers another way to control infected systems. It can also help the campaign continue if another command-and-control channel becomes unavailable.

The use of familiar cloud services adds another layer to the attack. Instead of relying only on an obvious malicious server, the attackers use a legitimate productivity platform to exchange commands and information.

Malware Includes Anti-Analysis Features

Seqrite’s analysis also found anti-analysis features in SheetAgent RAT. These checks can help the malware identify virtualised environments and sandbox systems used by security researchers.

When the malware detects signs of analysis, it can take steps to avoid examination. It also includes cleanup routines that can remove traces of its activity.

These features make the campaign harder to investigate and can help attackers maintain a lower profile after compromising a system.

Government, Education and Technology Users at Risk

Operation ShadowRecruit targets users across government, education and technology-related sectors in India. The campaign shows how attackers can use trusted themes and familiar services to make malware delivery more convincing.

Recruitment scams can be especially effective because job seekers often expect to receive documents related to vacancies, eligibility and applications. A file that appears to contain an important recruitment notice may therefore receive less scrutiny.

The campaign also reflects a wider change in cyber threats. Attackers increasingly use cloud and collaboration platforms during intrusion campaigns. They can combine legitimate tools with malicious files to create attack chains that are harder for users to identify.

Seqrite Highlights Wider Cyber Threat

The findings from Operation ShadowRecruit align with trends highlighted in Seqrite’s India Cyber Threat Report 2026. The report points to a growing shift towards stealthier and automation-assisted attacks.

The increasing use of cloud and collaboration platforms also forms part of this trend. Attackers can abuse services that users already know and trust instead of relying only on unfamiliar infrastructure.

Seqrite said organisations can use Seqrite DRPS to identify and disrupt external infrastructure linked to campaigns such as ShadowRecruit. This includes malicious domains, impersonation assets and other web-based threat surfaces.

Organisations that handle applicant, employee and operational records also need strong data protection. Seqrite Data Privacy can support organisations that need to protect sensitive information while meeting regulatory requirements. Seqrite said its products comply with the provisions of the DPDP Act.

Job Seekers Need to Verify Recruitment Files

Operation ShadowRecruit shows how attackers can turn a simple job opportunity into the entry point for a multi-stage malware campaign. The fake Cabinet Secretariat notice gives the attack a credible reason to reach potential victims.

Job seekers should therefore verify recruitment notices before opening unexpected ZIP archives or executable files. Organisations should also train employees and applicants to identify suspicious shortcuts, hidden scripts and unusual document attachments.

The campaign highlights a simple but important lesson: an official-looking recruitment notice does not always mean the file behind it is safe.

Subscribe Deshwale on YouTube

Join Our Whatsapp Group

Share.

Comments are closed.

Exit mobile version