APT Attacks Target Indian Government Using GOGITTER, GITSHELLPAD, and GOSHELL | Part 1
Essential information
- Published
- 26/01/2026 21:19
- Modified
- 27/01/2026 07:35
- Tags
- 2026-01-26 apt cobalt strike cobalt strike beacon github gitshellpad gogitter golang goshell government india pakistan
- Related entities
- 33 observables, 1 intrusion sets (apt), 6 techniques (mitre), 4 malware, 12 others
Description
A Pakistan-linked APT group conducted two campaigns targeting Indian government entities. The Gopher Strike campaign used PDFs with malicious links to deliver an ISO file containing GOGITTER, a Golang downloader that fetches payloads from private GitHub repositories. GITSHELLPAD, a Golang backdoor, was used for C2 communication via GitHub. GOSHELL, a Golang shellcode loader, deployed Cobalt Strike Beacon on specific hostnames. The attackers used various techniques including scheduled tasks for persistence, obfuscation, and environmental keying. Post-compromise activities involved system reconnaissance and data exfiltration. The campaign demonstrated sophisticated TTPs and custom-built tools, indicating a potentially new subgroup or parallel Pakistan-linked threat actor.