logo

APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2

ID: a4e69f63-cadb-5da3-b57c-accd037026d9

STIX ID: report--a4e69f63-cadb-5da3-b57c-accd037026d9

Feed Name: Security Boulevard

Threat Score
83/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Yin Hong Chang (Zscaler)

...
...

Zscaler ThreatLabz describes the Sheet Attack campaign (Nov 2025–Jan 2026) that uses PDF and LNK lures to deploy multiple backdoors—SHEETCREEP (C# using Google Sheets for C2), FIREPOWER (PowerShell using Firebase), and MAILCREEP (Go using Microsoft Graph)—alongside a PowerShell document stealer; the campaign abuses legitimate cloud services for covert C2, includes numerous IOCs (files, hashes, domains, IPs, Google Sheets C2 links), and shows indicators of generative-AI-assisted code development with medium-confidence attribution to a Pakistan-linked APT or an APT36 subgroup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.