Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job Seekers — Threadlinqs Intelligence
As of 2026-07-14, Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job Seekers is a high-severity malware threat attributed to APT36 (Pakistan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1297 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: APT36 · Pakistan · ESPIONAGE
Seqrite's APT Research Team disclosed Operation ShadowRecruit, a recruitment-themed espionage campaign targeting applicants for a Cabinet Secretariat 'Senior Field Officer (Technical)' posting in
Operation ShadowRecruit begins with a spearphishing lure themed around a genuine Cabinet Secretariat 'Senior Field Officer (Technical)' recruitment notice (Employment News, issue dated 13-19 June 2026) delivered to Indian government job applicants. The initial artifact is a Windows shortcut file, Document-24062026-Y6352634.lnk, disguised with a Microsoft Edge icon and a benign-sounding description ('Install ControlR Agent'). Executing the LNK invokes PowerShell in hidden mode to run a downloader script, JT-agenda.ps1, which retrieves the legitimate, Bitbound-signed ControlR RMM agent installer directly from demo.controlr.app and silently enrolls the victim endpoint into an attacker-controlled ControlR tenant using hardcoded enrollment credentials (Tenant ID, Key ID, Key Secret). This abuse of a legitimate, signed commercial RMM tool grants the operators full remote-hands-on-keyboard access while evading many security-tool trust heuristics that flag unsigned or unknown remote-access binaries.
In parallel, a 32-bit .NET dropper (Document.exe) stages a second, custom implant tracked as SheetAgent, extracting it (as agent.exe / WindowsDefenderSyncService.exe / MicrosoftSyncService.exe) into a working directory at %APPDATA%\Microsoft\WinSyncDefender\, alongside a decoy PDF-rendering shortcut (Document.lnk) that opens the genuine recruitment notice to distract the victim while the malware installs. The dropper establishes dual persistence via a scheduled task ('WindowsDefenderSyncService', triggered at logon and re-fired every three minutes) and a Startup-folder shortcut (WindowsDefenderSync.lnk), both masquerading as Windows Defender components.
SheetAgent is a custom .NET RAT whose most notable feature is its command-and-control channel: rather than (or in addition to) beaconing to a traditional C2 server, it authenticates to the Google Sheets and Google Drive APIs using a hardcoded Google Cloud service-account private key (service@sheet12-500308.iam.gserviceaccount.com, project sheet12-500308) and registers each victim as a row in a shared spreadsheet. Column A holds the victim hostname, B a timestamp, C attacker-issued commands, D command output, E the victim's public IP, F an ONLINE/ERROR status flag, H alerts, and J a URL-monitoring list. The implant polls Column C for new commands and writes results back to Column D, giving operators an encrypted-in-transit (HTTPS-to-Google), reputationally 'clean' C2 channel that blends into normal cloud/SaaS traffic and is difficult to block without disrupting legitimate Google Workspace usage. A second attacker-controlled server (38.242.157.89) hosts a decoy PDF plus three exposed web panels: SecureMonitor on port 9000, a 'PrivateRat' dashboard (developer alias 'HeartMelt') on port 7000, and an unnamed management interface on port 8000 - indicating this actor also operates or resells a broader RAT panel product alongside the bespoke SheetAgent tooling.
SheetAgent embeds an unusually extensive 14-point virtualization/sandbox-detection routine, checking WMI system-manufacturer strings, BIOS information, VM-associated disk-drive and GPU identifiers, running VMware/VirtualBox processes, VM-signature registry keys, VM-associated MAC address OUI prefixes, VM-specific drivers and installation directories, common sandbox analyst usernames, and known Any.Run and Triage sandbox artifacts, plus VM-specific devices/services. On positive detection the malware self-destructs via a dropped cleanup.bat that force-deletes the RAT executable, its service.json configuration file, and the batch script itself, minimizing forensic residue in automated analysis environments.
Seqrite attributes the campaign to APT36 (Transparent Tribe) with medium confidence, citing the recurring pattern of targeting Indian government job seekers, the multi-stage .NET malware architecture consistent with the group's known tradecraft, and - most significantly - the use of Google Sheets as a C2 channel, which overlaps with Zsca
Target sectors: government administration, education, technology
Target regions: india, South Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1204.002, T1059.001, T1106, T1053.005, T1547.001, T1053.005, T1133, T1548.004, T1036.005