logo

SHEETCREEP, FIREPOWER, and MAILCREEP Analysis

ID: cc683d92-380d-5880-9a7c-faef9f3a62ee

STIX ID: report--cc683d92-380d-5880-9a7c-faef9f3a62ee

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-01-27

Date Updated: 2026-05-01

...
...

### Executive summary This technical analysis describes an active multi-stage malware campaign (‘Sheet Attack’) that delivers backdoors (SHEETCREEP, FIREPOWER, MAILCREEP) via weaponized PDFs and LNK files, leverages cloud services (Google Sheets, Firebase, Microsoft Graph/Azure) for C2, employs persistence (scheduled tasks and loaders), and has been used to harvest documents and execute remote commands; the report also highlights operator activity and artifacts suggesting generative AI assisted in code authoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.