Google catches Beijing spies using Sheets to spread espionage across 4 continents
ID: 6b3b584c-6631-519f-88a4-cb856173ada8
STIX ID: report--6b3b584c-6631-519f-88a4-cb856173ada8
Feed Name: The Register (Security)
Google Threat Intelligence Group disrupted UNC2814 (a China-linked espionage crew) after discovering a campaign that targeted telecoms and government organizations across 42 countries using a novel Gridtide backdoor which leveraged Google Sheets API for C2; investigators found a disguised 'xapt' binary, lateral movement via SSH, privilege escalation, and use of SoftEther VPN for outbound encrypted connections, with 53 confirmed victims and suspected additional compromises. GTIG terminated the group's Google Cloud projects, disabled known infrastructure and accounts, and revoked the Sheets API calls used by the actor, and is supporting notified victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
