logo

A RAT in the spreadsheet.

ID: b05fe905-c42f-5418-96d8-4ae19c831e6d

STIX ID: report--b05fe905-c42f-5418-96d8-4ae19c831e6d

Feed Name: The CyberWire

Threat Score
85/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

...
...

Securonix researchers describe an evolved SHEETCREEP espionage campaign that uses a diplomatic-themed ISO phishing lure to deliver a C# remote-access trojan targeting Indian diplomatic interests; the malware leverages the Google Sheets API for stealthy C2 and researchers found 91 active victim tabs including a high-confidence target in Pakistan. The campaign is assessed with moderate confidence as linked to Pakistan-aligned APT36 and has incorporated XOR-obfuscated configurations and other anti-analysis measures to evade detection and maintain persistence. The full research and executive brief are available from Securonix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.