Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job Seekers
Operation ShadowRecruit (TL-2026-1297), also tracked as Operation ShadowRecruit, is a high-severity malware campaign, first published 2026-07-14. It is attributed to APT36 (Pakistan) with medium confidence, affects Microsoft Windows (LNK/Scheduled Task/Startup abuse), maps to 28 MITRE ATT&CK techniques (T1005, T1027.011, T1036.004), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1297
- Threat ID
- TL-2026-1297
- Also known as
- Operation ShadowRecruit, SheetAgent RAT campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- APT36
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Pakistan
- Motivation
- ESPIONAGE
- Target sectors
- government administration, education, technology
- Target regions
- india, South Asia
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Operation ShadowRecruit
Malware and tooling: Google Sheets API / Google Drive API
Seqrite's APT Research Team disclosed Operation ShadowRecruit, a recruitment-themed espionage campaign targeting applicants for a Cabinet Secretariat 'Senior Field Officer (Technical)' posting in India. A malicious LNK file masquerading as a Microsoft Edge document triggers a four-stage infection chain that installs the legitimate ControlR RMM agent for remote access alongside a custom .NET SheetAgent RAT that uses the Google Sheets API as a resilient, low-noise C2 channel. The campaign is attributed with medium confidence to APT36 (Transparent Tribe) based on targeting overlap and TTP similarity to the Zscaler-documented SheetCreep/Firepower/MailCreep cloud-C2 toolset.
How Operation ShadowRecruit works
Operation ShadowRecruit begins with a spearphishing lure themed around a genuine Cabinet Secretariat 'Senior Field Officer (Technical)' recruitment notice (Employment News, issue dated 13-19 June 2026) delivered to Indian government job applicants. The initial artifact is a Windows shortcut file, Document-24062026-Y6352634.lnk, disguised with a Microsoft Edge icon and a benign-sounding description ('Install ControlR Agent'). Executing the LNK invokes PowerShell in hidden mode to run a downloader script, JT-agenda.ps1, which retrieves the legitimate, Bitbound-signed ControlR RMM agent installer directly from demo.controlr.app and silently enrolls the victim endpoint into an attacker-controlled ControlR tenant using hardcoded enrollment credentials (Tenant ID, Key ID, Key Secret). This abuse of a legitimate, signed commercial RMM tool grants the operators full remote-hands-on-keyboard access while evading many security-tool trust heuristics that flag unsigned or unknown remote-access binaries.
In parallel, a 32-bit .NET dropper (Document.exe) stages a second, custom implant tracked as SheetAgent, extracting it (as agent.exe / WindowsDefenderSyncService.exe / MicrosoftSyncService.exe) into a working directory at %APPDATA%\Microsoft\WinSyncDefender\, alongside a decoy PDF-rendering shortcut (Document.lnk) that opens the genuine recruitment notice to distract the victim while the malware installs. The dropper establishes dual persistence via a scheduled task ('WindowsDefenderSyncService', triggered at logon and re-fired every three minutes) and a Startup-folder shortcut (WindowsDefenderSync.lnk), both masquerading as Windows Defender components.
SheetAgent is a custom .NET RAT whose most notable feature is its command-and-control channel: rather than (or in addition to) beaconing to a traditional C2 server, it authenticates to the Google Sheets and Google Drive APIs using a hardcoded Google Cloud service-account private key (service@sheet12-500308.iam.gserviceaccount.com, project sheet12-500308) and registers each victim as a row in a shared spreadsheet. Column A holds the victim hostname, B a timestamp, C attacker-issued commands, D command output, E the victim's public IP, F an ONLINE/ERROR status flag, H alerts, and J a URL-monitoring list. The implant polls Column C for new commands and writes results back to Column D, giving operators an encrypted-in-transit (HTTPS-to-Google), reputationally 'clean' C2 channel that blends into normal cloud/SaaS traffic and is difficult to block without disrupting legitimate Google Workspace usage. A second attacker-controlled server (38.242.157.89) hosts a decoy PDF plus three exposed web panels: SecureMonitor on port 9000, a 'PrivateRat' dashboard (developer alias 'HeartMelt') on port 7000, and an unnamed management interface on port 8000 - indicating this actor also operates or resells a broader RAT panel product alongside the bespoke SheetAgent tooling.
SheetAgent embeds an unusually extensive 14-point virtualization/sandbox-detection routine, checking WMI system-manufacturer strings, BIOS information, VM-associated disk-drive and GPU identifiers, running VMware/VirtualBox processes, VM-signature registry keys, VM-associated MAC address OUI prefixes, VM-specific drivers and installation directories, common sandbox analyst usernames, and known Any.Run and Triage sandbox artifacts, plus VM-specific devices/services. On positive detection the malware self-destructs via a dropped cleanup.bat that force-deletes the RAT executable, its service.json configuration file, and the batch script itself, minimizing forensic residue in automated analysis environments.
Seqrite attributes the campaign to APT36 (Transparent Tribe) with medium confidence, citing the recurring pattern of targeting Indian government job seekers, the multi-stage .NET malware architecture consistent with the group's known tradecraft, and - most significantly - the use of Google Sheets as a C2 channel, which overlaps with Zscaler ThreatLabz's prior reporting on the APT36-attributed SheetCreep, Firepower, and MailCreep cloud-abuse backdoor family targeting Indian government and diplomatic entities. APT36 (aka Transparent Tribe, Mythic Leopard, Earth Karkaddan, ProjectM, COPPER FIELDSTONE) is a Pakistan-aligned cyber-espionage actor active since at least 2013 with a long history of recruitment- and government-notice-themed lures against Indian military, diplomatic, and public-sector personnel, and has increasingly diversified its toolkit toward abuse of legitimate cloud APIs (Google Sheets/Drive, Microsoft Graph) for C2 to blend into normal SaaS traffic.
MITRE ATT&CK techniques used in TL-2026-1297
Collection
Defense Evasion
T1027.011 Fileless Storage; T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1127 Trusted Developer Utilities Proxy Execution; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564.001 Hidden Files and Directories
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1106 Native API; T1204.002 Malicious File
Persistence
T1053.005 Scheduled Task; T1133 External Remote Services; T1547.001 Registry Run Keys / Startup Folder
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery; T1614.001 System Language Discovery
Command and Control
T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Privilege Escalation
T1548.004 Elevated Execution with Prompt
Initial Access
T1566.001 Spearphishing Attachment
Resource Development
Affected products and versions in Operation ShadowRecruit
- Microsoft — Windows (LNK/Scheduled Task/Startup abuse)
Vulnerable versions: All supported Windows desktop/server versions - ControlR (Bitbound) — ControlR RMM Agent
Vulnerable versions: Legitimate agent abused via rogue tenant enrollment; no product vulnerability - Google — Google Sheets / Google Drive API
Vulnerable versions: Abused as a C2 transport via a compromised/attacker-created service account; no product vulnerability
Remediation for Operation ShadowRecruit
Immediate actions
- Block and alert on the attacker-controlled IP 38.242.157.89 and its exposed panel ports (7000, 8000, 9000) at perimeter/firewall/proxy
- Hunt for the scheduled task 'WindowsDefenderSyncService' and startup entry 'WindowsDefenderSync.lnk' masquerading as Windows Defender components
- Search endpoints for the working directory %APPDATA%\Microsoft\WinSyncDefender\ and files service.json / cleanup.bat
- Hash-match environment against the full IOC hash list (LNK, PS1, .NET dropper, SheetAgent variants, decoy documents, ControlR installer)
- Audit installed ControlR RMM agents for enrollment against the identified rogue Tenant ID (d5eab065-bbe2-4178-9574-1cbac7e40c64) and Key ID (319fe2d0-027e-4435-8b29-52af76a1972b); remove unauthorized enrollments
- Flag/monitor outbound traffic from endpoints to the Google Sheets/Drive API associated with service account service@sheet12-500308.iam.gserviceaccount.com and project sheet12-500308
- Warn recruitment-eligible government personnel about LNK-based email/portal lures themed on the Cabinet Secretariat 'Senior Field Officer (Technical)' posting
Workarounds
- Disable Windows Script Host / restrict .lnk execution from email and browser-downloaded content via Attack Surface Reduction rules
- Restrict outbound access to demo.controlr.app and other unauthorized RMM vendor domains at the proxy for non-IT-managed endpoints
Longer-term hardening
- Deploy EDR with behavioral detection for PowerShell-spawned-from-LNK execution chains and scheduled-task persistence masquerading as Defender services
- Implement application allowlisting / RMM governance to restrict which RMM tools (ControlR, AnyDesk, etc.) may be installed and which tenants employees may enroll into
- Deploy CASB/SSE inspection or DLP rules for anomalous Google Sheets/Drive API calls from endpoint processes (unusual for standard office workflows)
- Establish organization-wide LNK-attachment filtering/blocking at the email gateway for external senders
- Conduct recurring phishing-simulation and OPSEC training for recruitment-eligible personnel targeted by government-notice lures
Timeline of Operation ShadowRecruit
- Zscaler ThreatLabz uncovers three additional cloud-API-abuse backdoors (precursors to the SheetCreep/Firepower/MailCreep family later linked to APT36) during a September 2025 investigation.
- Start of the November 2025-January 2026 window in which Zscaler ThreatLabz observes active deployment of new APT36 cloud-C2 tooling (SheetCreep, Firepower, MailCreep) against Indian government and diplomatic targets.
- Zscaler ThreatLabz publishes analysis of the SheetCreep/Firepower/MailCreep cloud-API-abuse backdoor family attributed to APT36, establishing the Google Sheets-as-C2 TTP baseline later matched to SheetAgent.
- Operation ShadowRecruit infection chain observed active during June 2026, targeting Indian government job applicants with the recruitment-themed LNK lure.
- Genuine Cabinet Secretariat 'Senior Field Officer (Technical)' recruitment notice published in Employment News (issue window 13-19 June 2026), later repurposed as the campaign's decoy document.
- Malicious lure file Document-24062026-Y6352634.lnk built/staged, embedding the date 24062026 in its filename, indicating campaign preparation around this date.
- Seqrite Labs publishes a separate but temporally adjacent APT report, 'From Invoice to AnyDesk', covering a phishing campaign targeting Russian aerospace organizations, one week before the ShadowRecruit disclosure.
- Full IOC set released including file hashes for the LNK, PowerShell downloader, .NET dropper, SheetAgent variants, decoy PDF, and ControlR installer, plus attacker infrastructure at 38.242.157.89.
- Seqrite's APT Research Team (Priya Patel, Kartik Jivani, Shrutirupa Banerjiee) publishes 'Operation ShadowRecruit', disclosing the full infection chain, IOCs, and medium-confidence APT36 attribution.
Sources cited for Operation ShadowRecruit
- Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers
- SHEETCREEP, FIREPOWER, and MAILCREEP Analysis
- SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations
- Hackers Use UAE-India Diplomatic Lure to Deliver SHEETCREEP RAT via Google Sheets
- APT36: A Nightmare of Vibeware
- Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting India
- APT36: A Phishing Campaign Targeting Indian Government Entities
- APT36 : Multi-Stage LNK Malware Campaign Targeting Indian Government Entities
- APT Profile: Transparent Tribe aka APT36
- APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign
- Investigation Report: APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery
- Dark Web Profile: APT36
More in malware
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
Detection coverage for TL-2026-1297
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1297 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.