Pune: Seqrite, the enterprise security arm of Quick Heal Technologies Limited and a global provider of cybersecurity solutions, has uncovered key insights into Operation ShadowRecruit, a recruitment-themed malware campaign targeting Indian government job seekers through a fake recruitment notice for Senior Field Officer positions in the Cabinet Secretariat.
Operation ShadowRecruit uses a ZIP archive containing a malicious LNK file, a PowerShell script and a .NET executable to establish access, deploy a custom remote access trojan (RAT) and maintain a covert command-and-control (C2) channel.
Researchers at Seqrite Labs, India’s largest malware analysis facility, found that the attackers also abuse the legitimate ControlR remote management platform during the infection process.
The campaign then uses Google Sheets as a backup command-and-control channel for the final payload, which Seqrite has named SheetAgent RAT.
The malware registers infected systems in a spreadsheet, reads commands from attacker-controlled cells and writes execution results back to the spreadsheet.
This enables Operation ShadowRecruit to continue operating even if one command-and-control channel is disrupted.
How Operation ShadowRecruit Targets Indian Job Seekers
The campaign begins with a ZIP archive that appears to contain “approved documents”. However, the archive actually contains a malicious shortcut, a PowerShell downloader and a hidden executable.
The LNK file is disguised using a browser icon and launches the PowerShell stage in hidden mode. The PowerShell component downloads and enrolls the victim machine into ControlR before triggering the .NET dropper.
The dropper then establishes persistence through either a scheduled task or a startup shortcut.
At the same time, a decoy recruitment document is displayed on the victim’s screen to distract the target while the malware continues executing in the background.
The recruitment-themed approach used in Operation ShadowRecruit is specifically tailored to Indian job seekers, particularly those applying for government positions.
The campaign uses an official-looking recruitment notice to make the malicious file appear credible.
The decoy document imitates an official recruitment notice and includes details such as eligibility criteria, vacancies, application instructions and deadlines.
These elements are designed to keep victims focused on the fake employment opportunity while the malware executes in the background.
Also Read: GDAI Supernova to Incubate 15 Indian Game Studios in Three-Month Programme
SheetAgent RAT Uses Google Sheets for Command and Control
The final payload in Operation ShadowRecruit, named SheetAgent RAT by Seqrite, is designed to remain resilient and operationally flexible.
The malware uses hardcoded Google service account credentials to access Google Sheets and Google Drive APIs. This allows attackers to issue commands through spreadsheet cells, store information collected from victims and retrieve execution output from infected systems.
Seqrite’s analysis found that SheetAgent RAT also incorporates anti-analysis checks and cleanup routines. These capabilities help the malware evade virtualised environments and remove traces when it detects a sandbox.
By incorporating familiar cloud services into the attack chain, Operation ShadowRecruit enables the attackers to maintain communication with infected systems through commonly used productivity platforms.
Operation ShadowRecruit Targets Government, Education and Technology Users
According to Seqrite, the campaign affects government, education and technology-oriented users in India. The findings highlight how public-sector recruitment themes can be used to target multiple audiences.
Operation ShadowRecruit reflects a broader pattern in which attackers exploit trust in official-looking notices and familiar productivity tools to avoid suspicion, rather than depending solely on noisy malware delivery methods.
The threat also aligns with trends highlighted in Seqrite’s India Cyber Threat Report 2026, which documented a shift towards stealthier, automation-assisted attacks and the growing use of cloud and collaboration platforms in intrusion chains.
Seqrite Security Tools for Threat Detection and Data Protection
In this context, Seqrite DRPS can help organisations identify and disrupt external infrastructure supporting campaigns such as Operation ShadowRecruit, including malicious domains, impersonation assets and related web-based threat surfaces.
Seqrite Data Privacy also emerges as a security measure for organisations handling sensitive applicant, employee and operational records, as campaigns that begin with recruitment lures can potentially lead to credential theft or data exposure.
All Seqrite products are compliant with the provisions of the DPDP Act, helping organisations strengthen security and regulatory readiness.
Operation ShadowRecruit: Key Attack Stages
The campaign identified by Seqrite follows a multi-stage infection chain:
- Fake recruitment lure: Victims receive a ZIP archive presented as containing approved recruitment documents.
- Malicious LNK file: The archive contains a shortcut disguised with a browser icon.
- PowerShell execution: The LNK launches a PowerShell downloader in hidden mode.
- ControlR enrollment: The victim machine is downloaded and enrolled into the legitimate ControlR remote management platform.
- .NET dropper: The PowerShell stage triggers the .NET executable.
- Persistence: The dropper establishes persistence through a scheduled task or startup shortcut.
- Decoy document: A fake recruitment notice keeps the victim engaged while the malware operates in the background.
- SheetAgent RAT: The final payload uses Google Sheets and Google Drive APIs for command-and-control, victim information storage and execution output.
- Anti-analysis and cleanup: The malware uses checks and cleanup routines to evade sandbox environments and remove traces.
Seqrite’s findings on Operation ShadowRecruit show how a recruitment-themed lure, multi-stage malware delivery and legitimate cloud services can be combined within a single attack chain targeting Indian users.







