Pakistan-Linked Cyber Attacks on India Exposed with New Sophisticated Methods

by

Bhupendra Singh Chundawat

Pakistan-Linked Cyber Attacks on India Exposed with New Sophisticated Methods

New Delhi: Cybersecurity experts have uncovered highly advanced cyber attacks linked to Pakistan targeting Indian government institutions. According to a recent report, a threat actor operating from Pakistan launched two major cyber campaigns employing previously unrecorded and sophisticated techniques.

The cybersecurity firm Zscaler ThreatLabz first detected these campaigns in September 2025. Citing a report by the cybersecurity news portal ‘The Hacker News’, the campaigns have been named ‘Gopher Strike’ and ‘Sheet Attack’.

Researchers Sudeep Singh and Yin Hong Chang noted, “While some activities resemble those of the Pakistan-linked Advanced Persistent Threat (APT) group APT36, with moderate confidence, the assessment suggests these operations could be linked to a new subgroup or another parallel Pakistan-supported group.”

The report explains that the name ‘Sheet Attack’ originates from the use of legitimate services like Google Sheets, Firebase, and email for command and control (C2) purposes.

Meanwhile, the ‘Gopher Strike’ campaign involved phishing emails. Victims received PDF documents containing a blurred image with a simple pop-up urging users to download an Adobe Acrobat Reader DC update.

According to ‘The Hacker News’, users were prompted to install a “necessary update” to view the document. Clicking the fake “download and install” button triggered the download of an ISO image file, but only if the request originated from an Indian IP address and the user-agent indicated a Windows operating system.

Zscaler ThreatLabz highlighted that this server-side verification prevents automated URL analysis tools from downloading the ISO file, ensuring the malicious file reaches only its intended targets.

Earlier this month, another report revealed that Pakistan-linked hackers initiated a new espionage campaign targeting Indian government bodies and universities. The goal is to steal sensitive information using spyware and malware.

Leave a Comment

BREAKING NEWS: