logo

SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control

ID: d37c7ef4-a48d-5a9f-99bc-d9614ae566bd

STIX ID: report--d37c7ef4-a48d-5a9f-99bc-d9614ae566bd

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Do Son

...
...

Securonix reports a targeted campaign deploying SHEETCREEP, a C#.NET remote access trojan that uses Google Sheets API as a covert command-and-control channel; the campaign used a diplomatic-themed ISO with a malicious LNK to infect primarily Indian diplomatic and foreign-affairs entities, achieving 91 active spreadsheet tabs (including sandboxes and researcher labs) and employing persistence via COM-created scheduled tasks, in-process PowerShell, XOR-obfuscated configs, and embedded GCP service account credentials, with suspected (moderate confidence) attribution to APT36.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.