Indian government entities have been targeted in two sophisticated cyberattack campaigns, codenamed Gopher Strike and Sheet Attack, by a threat actor operating from Pakistan. These campaigns, identified in September 2025, utilize previously undocumented tradecraft, including legitimate services for command-and-control, according to a recent report by The Hacker News.The Sheet Attack campaign leverages services like Google Sheets and Firebase for command-and-control. Gopher Strike begins with phishing emails containing PDF documents that trick recipients into downloading a fake Adobe Acrobat Reader DC update. This fake update, delivered as an ISO image, contains a Golang-based downloader called GOGITTER. GOGITTER establishes persistence via scheduled tasks and fetches further malicious scripts and payloads, including a backdoor named GITSHELLPAD, from GitHub repositories. The threat actor also employs tools to gather system information and deploy Cobalt Strike beacon, with an effort to evade antivirus detection by inflating file sizes and using specific hostname checks.Source: The Hacker News
Threat Intelligence, Malware, Government security
New Pakistan-linked campaigns target Indian government entities

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



