News·3 min read

Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants

Indian government job seekers are being targeted in a multi-stage malware campaign that uses a fake Cabinet Secretariat recruitment notice to deploy both a legitimate remote-management tool and a cust

CS
CyberShield Team
2026-07-15
Share:
Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants

Indian government job seekers are being targeted in a multi-stage malware campaign that uses a fake Cabinet Secretariat recruitment notice to deploy both a legitimate remote-management tool and a custom remote-access Trojan (RAT). Researchers at Seqrite’s APT Research Team dubbed the activity “Operation ShadowRecruit.” The campaign targets applicants for Senior Field Officer (Technical) roles. It […] The post Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants appeared first on Cyber Security News.

Indian government job seekers are being targeted in a multi-stage malware campaign that uses a fake Cabinet Secretariat recruitment notice to deploy both a legitimate remote-management tool and a custom remote-access Trojan (RAT). Researchers at Seqrite’s APT Research Team dubbed the activity “Operation ShadowRecruit.” The campaign targets applicants for Senior Field Officer (Technical) roles. It uses a ZIP archive named Approved Documents 2026.pdf.zip as the initial lure. Seqrite assessed with medium confidence that the activity may be linked to the Pakistan-aligned APT36 threat group. The archive contains three files: Document.exe, Document-24062026-Y6352634.lnk, and JT-agenda.ps1. Only the LNK shortcut is visible by default, while the PowerShell script and executable use the Hidden file attribute. Attackers gave the shortcut a Microsoft Edge icon to make it appear to be a harmless document. The LNK file silently launches PowerShell in hidden, non-interactive mode and executes JT-agenda. LNK-PowerShell Deploys Dual RATs The PowerShell script contains a Base64-encoded command that downloads the legitimate ControlR Agent installer from demo.controlr.app. ControlR is a remote monitoring and management (RMM) product signed by Bitbound. In this case, the attackers allegedly used hardcoded enrollment details to register compromised devices with their own ControlR tenant. LNK-PowerShell Deploys Dual RATs (Source: seqrite) Once enrolled, a victim system could be remotely managed by the operators, enabling command execution, file transfers, and activity monitoring. The script then runs Document.exe, initiating the next part of the infection chain. Document.exe is a 323232-bit .NET dropper. It creates a directory at %APPDATA%\Microsoft\WinSyncDefender, a name designed to resemble a Windows security component. The dropper extracts two embedded files: agent.exe, the final RAT payload, and Document.lnk, which retrieves and displays a decoy PDF. LNK-PowerShell Deploys Dual RATs (Source: seqrite) The RAT also contains extensive anti-analysis checks. Seqrite found 141414 virtualization-detection routines that inspect BIOS data, WMI details, processes, registry keys, MAC addresses, drivers, and sandbox artifacts. If it detects a virtual machine or a malware analysis environment, it launches a cleanup process to delete itself and related files. Researchers also identified several management panels on the same server, including SecureMonitor on port 9000, PrivateRat on port 7000, and another password-protected panel on port 8000. The PrivateRat interface listed “HeartMelt” as its developer name. Organizations should warn job seekers against opening recruitment files delivered through untrusted channels, especially ZIP archives containing LNK files. Security teams should monitor for suspicious PowerShell activity, ControlR enrollments, scheduled tasks that resemble Windows Defender services, and Google Sheets API traffic originating from endpoints. Indicators of Compromise IOC TypeIndicatorSHA-256 / DetailsZIP ArchiveApproved Documents 2026.pdf.zip2b33b5185e93e1655eb27dbaa025d7ee088627db3d640fe4709be705646b189cExecutableDocument.exeee9dd2a180aea75af5c0eda16b Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google. The post Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.