SHEETCREEP Espionage Campaign Uses UAE-India Lure for RAT Deployment
ID: d5665cf5-f499-5714-9207-dee231c22ec9
STIX ID: report--d5665cf5-f499-5714-9207-dee231c22ec9
Feed Name: ThreatCluster
SHEETCREEP is an espionage campaign that delivers a C# remote access trojan via a diplomatic-themed ISO (UAE-India_Strategic_Partnership_Week.iso) which launches a dropper from a LNK file to install the RAT and present a decoy PDF; the malware uses the Google Sheets API as its command-and-control channel by creating unique tabs per victim, with researchers identifying 91 active victim tabs (including targets in Islamabad) and noting advanced anti-analysis and obfuscation techniques that complicate detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
