APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2
ID: a4e69f63-cadb-5da3-b57c-accd037026d9
STIX ID: report--a4e69f63-cadb-5da3-b57c-accd037026d9
Feed Name: Security Boulevard
Zscaler ThreatLabz describes the Sheet Attack campaign (Nov 2025–Jan 2026) that uses PDF and LNK lures to deploy multiple backdoors—SHEETCREEP (C# using Google Sheets for C2), FIREPOWER (PowerShell using Firebase), and MAILCREEP (Go using Microsoft Graph)—alongside a PowerShell document stealer; the campaign abuses legitimate cloud services for covert C2, includes numerous IOCs (files, hashes, domains, IPs, Google Sheets C2 links), and shows indicators of generative-AI-assisted code development with medium-confidence attribution to a Pakistan-linked APT or an APT36 subgroup.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
