{"id":207194,"date":"2026-01-27T11:45:00","date_gmt":"2026-01-27T16:45:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/01\/27\/experts-detect-pakistan-linked-cyber-campaigns-aimed-at-indian-government-entities\/"},"modified":"2026-01-27T20:40:08","modified_gmt":"2026-01-28T01:40:08","slug":"experts-detect-pakistan-linked-cyber-campaigns-aimed-at-indian-government-entities","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/01\/27\/experts-detect-pakistan-linked-cyber-campaigns-aimed-at-indian-government-entities\/","title":{"rendered":"Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/experts-detect-pakistan-linked-cyber.html\">Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/experts-detect-pakistan-linked-cyber.html\">https:\/\/thehackernews.com\/2026\/01\/experts-detect-pakistan-linked-cyber.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-27 11:45:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Jan 27, 2026<\/span><\/span><span class=\"p-tags\">Threat Intelligence \/ Cyber Espionage<\/span><\/p>\n<p>Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft.<\/p>\n<p>The campaigns have been codenamed <strong>Gopher Strike<\/strong> and <strong>Sheet Attack<\/strong> by Zscaler ThreatLabz, which identified them in September 2025.<\/p>\n<p>&#8220;While these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT) group, APT36, we assess with medium confidence that the activity identified during this analysis might originate from a new subgroup or another Pakistan-linked group operating in parallel,&#8221; researchers Sudeep Singh and Yin Hong Chang said.<\/p>\n<p>Sheet Attack gets its name from the use of legitimate services like Google Sheets, Firebase, and email for command-and-control (C2). On the other hand, Gopher Strike is assessed to have leveraged phishing emails as a starting point to deliver PDF documents containing a blurred image that&#8217;s superimposed by a seemingly harmless pop-up instructing the recipient to download an update for Adobe Acrobat Reader DC.<\/p>\n<p><img decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqlhh16hjmE7NRyQeAR2_sLZ1uDwyQH2jkPHmDTAtveTHoIjCrfmK6JLqlZuNKOPG1RGLtwJk-ZJDwQiV-McwmzAUu1iOSwwMjs_tqI1KjcL_tCvc0M2XuKBPfJ1RXpKxnx-eGdWwM0wlNDnUYHvXr-1LZk2zRmDNLIEbYGalGQJsd6QwC0pyCrLavN0fz\/s728-e100\/threatlocker-inside-d.png\" width=\"729\" height=\"91\"\/><\/p>\n<p>The main purpose of the image is to give the users an impression that it&#8217;s necessary to install the update in order to access the document&#8217;s contents. Clicking the &#8220;Download and Install&#8221; button in the fake update dialog triggers the download of an ISO image file only when the requests originate from IP addresses located in India and the User-Agent string corresponds to Windows.<\/p>\n<p>&#8220;These server-side checks prevent automated URL analysis tools from fetching the ISO file, ensuring that the malicious file is only delivered to intended targets,&#8221; Zscaler said.<\/p>\n<p>The malicious payload embedded within the ISO image is a Golang-based downloader dubbed GOGITTER that&#8217;s responsible for creating a Visual Basic Script (VBScript) file if it does not already exist in the following locations: &#8220;C:UsersPublicDownloads,&#8221; &#8220;C:UsersPublicPictures,&#8221; and &#8220;%APPDATA%.&#8221; The script is&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/experts-detect-pakistan-linked-cyber.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities https:\/\/thehackernews.com\/2026\/01\/experts-detect-pakistan-linked-cyber.html Publish Date: 2026-01-27 11:45:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":207195,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiG612WfAM4qjKPdbLvz7i_kK0qgRz5Abg8pRz9uGc86pEQvuO-_83uNd8xC8e1y86mWhlTRL_PeWtgp2bfizGf8y78pp1xGYqoXJ9Q7ilpXG4lAS4MvNiiAMGf74PzFod56EJW9qq6P3afCB9IgTFGrbgu1EqnXVsly_I8clrUqdGReHfmEJtKUL09wV5m\/s1700-e365\/attack.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,25,34],"class_list":["post-207194","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-phishing","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207194"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=207194"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207194\/revisions"}],"predecessor-version":[{"id":207196,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207194\/revisions\/207196"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/207195"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=207194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=207194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=207194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}