Seqrite Uncovers ShadowRecruit Malware Targeting Indian Job Seekers

https://www.itvoice.in/wp-content/uploads/2026/08/Copy-of-Redington-2026-08-19T144115.292.jpg

Seqrite, the enterprise security arm of Quick Heal Technologies Limited, a global provider of cybersecurity solutions, has unveiled key insights into Operation ShadowRecruit, a recruitment-themed malware campaign targeting Indian government job seekers through a fake recruitment notice for Senior Field Officer positions in the Cabinet Secretariat. The campaign uses a ZIP archive containing a malicious LNK file, a PowerShell script, and a .NET executable to establish access, deploy a custom remote access trojan and maintain a covert command-and-control channel.

Researchers at Seqrite Labs, India’s largest malware analysis facility, found that the attackers also abuse the legitimate ControlR remote management platform during infection, then fall back on Google Sheets as a backup command-and-control channel for the final payload, which Seqrite names SheetAgent RAT. The malware registers infected systems in a spreadsheet, reads commands from attacker-controlled cells and writes results back, allowing the operation to continue even when one channel is disrupted.

...

Copyright of this story solely belongs to itvoice.in. To see the full text click HERE

Read more