SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control
ID: d37c7ef4-a48d-5a9f-99bc-d9614ae566bd
STIX ID: report--d37c7ef4-a48d-5a9f-99bc-d9614ae566bd
Feed Name: securityonline.info
Securonix reports a targeted campaign deploying SHEETCREEP, a C#.NET remote access trojan that uses Google Sheets API as a covert command-and-control channel; the campaign used a diplomatic-themed ISO with a malicious LNK to infect primarily Indian diplomatic and foreign-affairs entities, achieving 91 active spreadsheet tabs (including sandboxes and researcher labs) and employing persistence via COM-created scheduled tasks, in-process PowerShell, XOR-obfuscated configs, and embedded GCP service account credentials, with suspected (moderate confidence) attribution to APT36.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
