logo

APT41 - Google Sheets as C2

ID: 7268f67e-ca6f-53e8-a6c0-f927cb1f91dc

STIX ID: report--7268f67e-ca6f-53e8-a6c0-f927cb1f91dc

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2024-09-05

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report highlights GC2, a command-and-control tool that leverages Google Sheets and Drive (or Microsoft SharePoint) for tasking and exfiltration, and summarizes Google TAG’s findings on APT41 using GC2 against a Taiwanese media organization. The attack began with a phishing email leading to a password-protected Google Drive payload, after which GC2 enabled command retrieval from Google Sheets, data exfiltration via Google Drive, and downloading of additional files. It underscores the growing use of publicly available tools and cross-platform Go-based malware to blend malicious traffic with legitimate cloud services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.