logo

Hackers Use UAE-India Diplomatic Lure to Deliver SHEETCREEP RAT via Google Sheets

ID: c3cafec8-cd33-5fd0-bcb3-35834d00d228

STIX ID: report--c3cafec8-cd33-5fd0-bcb3-35834d00d228

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Mayura Kathir

...
...

SHEETCREEP is an active espionage campaign delivering a compact .NET remote access trojan via a deceptive UAE‑India diplomatic ISO/LNK lure; the RAT persists via a scheduled task, executes PowerShell in‑process, and uses an embedded GCP service‑account to operate Google Sheets as a covert C2 channel. Securonix recovered credentials, accessed the live spreadsheet, enumerated ~91 victim tabs (including high‑confidence targets), and observed strong evasion and counter‑forensics, with attribution assessed at moderate confidence to APT36.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.