{"id":10167,"date":"2026-01-27T10:03:38","date_gmt":"2026-01-27T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/27\/apt-hackers-attacking-indian-government-using-gogitter-tool-and-gitshellpad-malware\/"},"modified":"2026-01-27T10:03:38","modified_gmt":"2026-01-27T10:03:38","slug":"apt-hackers-attacking-indian-government-using-gogitter-tool-and-gitshellpad-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/27\/apt-hackers-attacking-indian-government-using-gogitter-tool-and-gitshellpad-malware\/","title":{"rendered":"APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware"},"content":{"rendered":"<p>    APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. <\/p>\n<p>The campaign, identified as Gopher Strike, emerged in September 2025 and represents a significant escalation in targeted cyber operations against sensitive government infrastructure. <\/p>\n<p>This coordinated assault demonstrates the growing sophistication of state-sponsored threat actors who continue refining their technical capabilities and operational procedures.<\/p>\n<p>The attack chain begins with carefully crafted <a href=\"https:\/\/cybersecuritynews.com\/hr-it-related-phishing-emails-are-top-clicked\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing emails<\/a> containing deceptive PDF documents that impersonate legitimate government communications. <\/p>\n<p>These PDFs display blurred images of official documents and use social engineering tactics to trick recipients into downloading an ISO file by clicking a button labeled \u201cDownload and Install,\u201d which appears to request a fake Adobe Acrobat update.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgZjYv-iuYovCVpb5rJYS5C03ftZSz4sTECvLxJvYP7gSFZDg98jhMb1lc5JbhqovD70htKzzRTmKR7DBqJfyoGKZlG5h3sVXzvjf_9QLww4LK1jPTgwpbD358jsBlNOsowVVTjMDrP5ogbHRnYQmcRAdoJmJ88CChYnoY1nhBdT4p2vQ5tRuw_b5Fkk0g\/s16000\/Gopher%2520Strike%2520campaign%2520leads%2520to%2520the%2520deployment%2520of%2520Cobalt%2520Strike%2520%28Source%2520-%2520Zscaler%29.webp?ssl=1\" alt=\"Example of a PDF file used in the Gopher Strike campaign (Source - Zscaler) \"><figcaption class=\"wp-element-caption\">Example of a PDF file used in the Gopher Strike campaign (Source \u2013 Zscaler) <\/figcaption><\/figure>\n<\/div>\n<p>The malicious ISO file remains dormant until activated, containing hidden <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> designed to establish persistent access to compromised systems.<\/p>\n<p>The infection mechanism relies on three custom-built tools written in Golang that work in concert to establish control over targeted machines. <\/p>\n<p>Zscaler analysts and researchers <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/apt-attacks-target-indian-government-using-gogitter-gitshellpad-and-goshell\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> GOGITTER as the initial downloader component that fetches additional payloads from threat actor-controlled GitHub repositories using embedded authentication tokens. <\/p>\n<p>Once deployed, GOGITTER creates a VBScript file called windows_api.vbs that continuously polls command-and-control servers every 30 seconds, checking for new instructions to execute on the infected machine.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-gitshellpad-s-innovative-github-based-persistence-mechanism\"><strong>GITSHELLPAD\u2019s Innovative GitHub-Based Persistence Mechanism<\/strong><\/h2>\n<p>GITSHELLPAD represents the campaign\u2019s most distinctive element, functioning as a lightweight backdoor that leverages private GitHub repositories for all command-and-control communication. <\/p>\n<p>This approach allows the threat actor to hide malicious traffic within legitimate-looking GitHub activity, making detection significantly more difficult for security monitoring tools. <\/p>\n<p>Upon infection, GITSHELLPAD registers the victim by creating a new directory in the threat actor\u2019s private repository using the format SYSTEM-[hostname], then adds an info.txt file containing Base64-encoded system information about the compromised machine.<\/p>\n<p>The backdoor polls GitHub\u2019s API every 15 seconds for new instructions stored in a command.txt file, allowing operators to remotely execute <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> commands, download additional tools, or stage further malware deployments. <\/p>\n<p>This design proves particularly effective because it avoids traditional network indicators while maintaining reliable two-way communication through a service millions of organizations already trust and whitelist for legitimate development purposes.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEisKWY24Ws74cVYKJjclNfKzZV3t-lWHOkc9nFYvfNyS4lyH9cRLhqjGGduJejwz1Xj0b4jjIpcmIYz6qgFBuwTGlPfnLKj0w6dAiSsbBgXxKdC8meCkuBO0yXH_jvdn3nle4DJo8ZwQA8mIaTAs2p-xpDA8NC4k7u55jLlqNIS_1UokFRp4xkxTcLWTEg\/s16000\/Example%2520of%2520a%2520PDF%2520file%2520used%2520in%2520the%2520Gopher%2520Strike%2520campaign%2520%28Source%2520-%2520Zscaler%29.webp?ssl=1\" alt=\"Gopher Strike campaign leads to the deployment of Cobalt Strike (Source - Zscaler)\"><figcaption class=\"wp-element-caption\">Gopher Strike campaign leads to the deployment of Cobalt Strike (Source \u2013 Zscaler)<\/figcaption><\/figure>\n<\/div>\n<p>The final stage involves deploying <a href=\"https:\/\/cybersecuritynews.com\/hackers-delivering-cobalt-strike-beacon\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cobalt Strike<\/a> Beacon through GOSHELL, a custom shellcode loader that executes only on machines with specific hardcoded hostnames, further restricting the payload to intended targets. <\/p>\n<p>Security researchers continue tracking this evolving threat to protect government networks against future attacks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apt-hackers-attacking-indian-government-using-gogitter-tool\/\">APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apt-hackers-attacking-indian-government-using-gogitter-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. The campaign, identified as Gopher Strike, emerged in September 2025 and represents a significant escalation in targeted cyber [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10167","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10167"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10167"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10167\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}