Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities
A threat actor operating in Pakistan has used previously unreported tradecraft to attack Indian government agencies in two campaigns.
Zscaler ThreatLabz discovered the campaigns in September 2025 and nicknamed them Gopher Strike and Sheet Attack.
Researchers Sudeep Singh and Yin Hong Chang stated, We assess with medium confidence that the activity identified during this analysis might originate from a new subgroup or another Pakistan-linked group operating in parallel, even though these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT) group, APT36.
The use of reputable services like Google Sheets, Firebase, and email for command-and-control (C2) is how Sheet Attack got its moniker. However, it is determined that Gopher Strike used phishi...


