SheetAgent RAT Runs 14 Virtual Machine Checks and Self-Deletes When Analysis Is Detected
ID: b32a753d-3cd5-5940-a476-b57715ced7e6
STIX ID: report--b32a753d-3cd5-5940-a476-b57715ced7e6
Feed Name: GBHackers
**Executive summary:** Seqrite APT Research Team documents a targeted campaign that lures Indian government job seekers with a fake recruitment notice to deploy SheetAgent RAT; the attack chain uses a ZIP containing an LNK, a hidden PowerShell script, and a .NET dropper which installs a legitimate ControlR RMM for persistent hands-on access and renames the RAT to blend in, while SheetAgent uses hardcoded Google service-account credentials to operate Google Sheets/Drive as a covert C2, includes extensive VM/sandbox anti-analysis checks and self-deletion capabilities, and is attributed with medium confidence to APT36; IOCs and hashes are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
