logo

SheetAgent RAT Runs 14 Virtual Machine Checks and Self-Deletes When Analysis Is Detected

ID: b32a753d-3cd5-5940-a476-b57715ced7e6

STIX ID: report--b32a753d-3cd5-5940-a476-b57715ced7e6

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Mayura Kathir

...
...

**Executive summary:** Seqrite APT Research Team documents a targeted campaign that lures Indian government job seekers with a fake recruitment notice to deploy SheetAgent RAT; the attack chain uses a ZIP containing an LNK, a hidden PowerShell script, and a .NET dropper which installs a legitimate ControlR RMM for persistent hands-on access and renames the RAT to blend in, while SheetAgent uses hardcoded Google service-account credentials to operate Google Sheets/Drive as a covert C2, includes extensive VM/sandbox anti-analysis checks and self-deletion capabilities, and is attributed with medium confidence to APT36; IOCs and hashes are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.