Unveiling Pakistan-Linked Cyber Threats Targeting Indian Government Entities
Identified Campaigns: Gopher Strike and Sheet Attack
In a significant revelation, cybersecurity firm Zscaler ThreatLabz has detected two cyber campaigns, codenamed Gopher Strike and Sheet Attack, that have targeted Indian government entities. These campaigns were first identified in September 2025.
While these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT) group, APT36, the researchers assess with medium confidence that the activity may originate from a new subgroup or another Pakistan-linked group operating in parallel.
Unique Tactics: Evasion and Command-and-Control (C2)
The Sheet Attack campaign uses legitimate services like Google Sheets, Firebase, and email for command-and-control (C2). On the other hand, Gopher Strike is believed to have leveraged phishing emails as a starting point to deliver malicious PDF documents.
In an interesting twist, Gopher Strike adds junk bytes to the Portable Executable (PE) overlay, likely to evade detection by antivirus software. This technique, known as GOSHELL, only executes on specific hostnames by comparing the victim's hostname against a hard-coded list.
Relevance to North East India and India
The cyber threats targeting Indian government entities pose a significant risk to the nation's security and digital infrastructure. As India continues to digitize its services and infrastructure, the importance of cybersecurity becomes increasingly vital, especially in a region like North East India, which is a significant contributor to India's digital economy.
Implications and Future Threats
The detection of these campaigns serves as a reminder of the ongoing cyber threats facing India and the need for robust cybersecurity measures. As the nature of cyber threats evolves, it is crucial for organizations and governments to stay vigilant and adapt their security strategies accordingly.
While the exact source of these campaigns remains unconfirmed, the use of undocumented tradecraft indicates a sophisticated adversary. Further investigations are necessary to understand the full extent of these threats and to develop effective countermeasures.