logo

SHEETCREEP Espionage Campaign Uses UAE-India Lure for RAT Deployment

ID: d5665cf5-f499-5714-9207-dee231c22ec9

STIX ID: report--d5665cf5-f499-5714-9207-dee231c22ec9

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

...
...

SHEETCREEP is an espionage campaign that delivers a C# remote access trojan via a diplomatic-themed ISO (UAE-India_Strategic_Partnership_Week.iso) which launches a dropper from a LNK file to install the RAT and present a decoy PDF; the malware uses the Google Sheets API as its command-and-control channel by creating unique tabs per victim, with researchers identifying 91 active victim tabs (including targets in Islamabad) and noting advanced anti-analysis and obfuscation techniques that complicate detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.