Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026

SolarWinds Web Help Desk Vulnerability Actively Exploited

February 6, 2026
Facebook X (Twitter) Instagram
Friday, February 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities
News

Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

Team-CWDBy Team-CWDFebruary 2, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft.

The campaigns have been codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, which identified them in September 2025.

“While these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT) group, APT36, we assess with medium confidence that the activity identified during this analysis might originate from a new subgroup or another Pakistan-linked group operating in parallel,” researchers Sudeep Singh and Yin Hong Chang said.

Sheet Attack gets its name from the use of legitimate services like Google Sheets, Firebase, and email for command-and-control (C2). On the other hand, Gopher Strike is assessed to have leveraged phishing emails as a starting point to deliver PDF documents containing a blurred image that’s superimposed by a seemingly harmless pop-up instructing the recipient to download an update for Adobe Acrobat Reader DC.

The main purpose of the image is to give the users an impression that it’s necessary to install the update in order to access the document’s contents. Clicking the “Download and Install” button in the fake update dialog triggers the download of an ISO image file only when the requests originate from IP addresses located in India and the User-Agent string corresponds to Windows.

“These server-side checks prevent automated URL analysis tools from fetching the ISO file, ensuring that the malicious file is only delivered to intended targets,” Zscaler said.

The malicious payload embedded within the ISO image is a Golang-based downloader dubbed GOGITTER that’s responsible for creating a Visual Basic Script (VBScript) file if it does not already exist in the following locations: “C:UsersPublicDownloads,” “C:UsersPublicPictures,” and “%APPDATA%.” The script is designed to fetch VBScript commands every 30 seconds from two pre-configured C2 servers.

GOGITTER also sets up persistence using a scheduled task that’s configured to run the aforementioned VBScript file every 50 minutes. In addition, it ascertains the presence of another file named “adobe_update.zip” in the same three folders. If the ZIP file is not present, it pulls the archive from a private GitHub repository (“github[.]com/jaishankai/sockv6”). The GitHub account was created on June 7, 2025.

Once the download is successful, the attack chain sends an HTTP GET request to the domain “adobe-acrobat[.]in” likely to signal the threat actors that the endpoint has been infected. GOGITTER then extracts and executes “edgehost.exe” from the ZIP file. A lightweight Golang-based backdoor, GITSHELLPAD, leverages threat actor-controlled private GitHub repositories for C2.

Specifically, it polls the C2 server every 15 seconds by means of a GET request to access the contents of a file named “command.txt.” It supports six different commands –

  • cd .., to change working directory to the parent directory
  • cd, to change directory to the specified path
  • run, to run a command in the background without capturing the output
  • upload, to upload a local file specified by the path to the GitHub repository
  • download, to download a file to the specified path
  • default case, to run a command using cmd /c and capture the output
Cybersecurity

The results of the command execution are stored in a file called “result.txt” and uploaded to the GitHub account via an HTTP PUT request. The “command.txt” is then deleted from the GitHub repository once the command is successfully executed.

Zscaler said it observed the threat actor also downloading RAR archives using cURL commands after gaining access to the victim’s machine. The archives include utilities to gather system information and drop GOSHELL, a bespoke Golang-based loader used to deliver Cobalt Strike Beacon after multiple rounds of decoding. The tools are wiped from the machine after use.

“GOSHELL’s size was artificially inflated to approximately 1 gigabyte by adding junk bytes to the Portable Executable (PE) overlay, likely to evade detection by antivirus software,” the cybersecurity company said. “GOSHELL only executes on specific hostnames by comparing the victim’s hostname against a hard-coded list.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNotepad++ Update Hijacking Linked to Hosting Provider Compromise
Next Article Former Google Engineer Found Guilty of Stealing AI Secrets
Team-CWD
  • Website

Related Posts

News

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026
News

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026
News

SolarWinds Web Help Desk Vulnerability Actively Exploited

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

How the always-on generation can level up their cybersecurity game

September 11, 2025

Your information is on the dark web. What happens next?

January 13, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.