Seqrite uncovers the hidden threat behind Operation ShadowRecruit

DQChannels Bureau
DQChannels Bureau
Seqrite uncovers the hidden threat behind Operation ShadowRecruit

Operation ShadowRecruit is targeting Indian government job seekers through a fake recruitment notice for Senior Field Officer positions in the Cabinet Secretariat. According to Seqrite, the campaign uses a multi-stage infection chain to establish access and deploy a custom remote access Trojan.

The attack begins with a ZIP archive presented as containing approved documents. Instead, it carries a malicious shortcut, a PowerShell script and a hidden .NET executable. A decoy recruitment document then keeps the victim focused on the fake opportunity while the malware works in the background.

The approach is notable because the lure is built around a familiar process: looking for a government job.

Multi-stage malware hides behind a familiar process

The campaign uses multi-stage malware rather than relying on a single malicious file. The LNK file is disguised with a browser icon and launches the PowerShell stage in hidden mode. The infection then uses the ControlR remote management platform before triggering the .NET dropper.

Persistence is created through a scheduled task or startup shortcut. Seqrite researchers also found that the attackers use Google Sheets as a backup command-and-control channel.

That makes the campaign more than a simple fake recruitment document. It is designed to keep operating when one communication route is disrupted.

Indian job seekers become the main target

The targeting of Indian job seekers is central to the campaign. The fake recruitment document includes eligibility criteria, vacancies, application instructions and deadlines.

This detail matters because the document is designed to look useful rather than suspicious. The victim has a reason to open it and spend time reading it.

The campaign also affects users across government, education and technology-oriented organisations in India. The common thread is trust in official-looking recruitment material.

A fake recruitment campaign uses familiar tools

The Fake recruitment campaign also uses Google Sheets and Google Drive APIs through hardcoded Google service account credentials. Seqrite says the final payload, named SheetAgent RAT, can register infected systems in a spreadsheet, receive commands through attacker-controlled cells and return execution results.

The malware also includes anti-analysis checks and cleanup routines, according to the analysis.

The wider lesson from the campaign is simple. Familiar cloud and productivity tools can become part of an intrusion chain when attackers find ways to blend malicious activity into normal-looking workflows.

Operation ShadowRecruit shows where the risk begins

Operation ShadowRecruit highlights how a job scam malware vector can start with something as ordinary as a recruitment notice. The campaign does not depend only on technical tricks. Its strength comes from combining a believable lure with a multi-stage attack and familiar online services.

For organisations, the supplied analysis points to the need to watch the external infrastructure supporting such campaigns, including malicious domains and impersonation assets. It also highlights the risk to applicant, employee and operational data when recruitment-themed attacks move beyond the initial lure.

The campaign ultimately shows why security teams need to look beyond the malware file itself. The first warning may be hidden in the story used to convince someone to open it.

Read More: 

CSM Technologies MOSIP adoption signals a wider GovTech push

Tiger Analytics appoints Prakash Arunachalam amid IPO plans

Barracuda finds 20 flaws in web application security

GIGABYTE Launches AORUS GeForce RTX 50 Series INFINITY Graphics Cards

Latest Stories