GC2 (Google Command and Control) is an open-source, Go-based command-and-control and post-exploitation/red teaming tool. It is designed to blend malicious traffic with legitimate cloud services by using Google Sheets for tasking/command execution and Google Drive for payload delivery and data exfiltration; reporting also notes variants that can use Microsoft SharePoint List and SharePoint documents for similar purposes. On compromised devices, the GC2 agent connects to a Google Sheets URL to receive commands, can download and install additional payloads from Google Drive, and can exfiltrate stolen data to Google Drive. High-confidence reporting links GC2 to Chinese state-sponsored APT41 activity in 2022/2023, including attacks against a Taiwanese media organization and an Italian job search company; in the Taiwanese case, Google reported a phishing campaign in which password-protected files hosted on Google Drive delivered the GC2 agent. GC2 was also observed in a May 2025 Fog ransomware intrusion against a financial institution in Asia, where it was used alongside other open-source tools including Adaptix and Stowaway; Symantec reported GC2 enabled command execution and file exfiltration and noted this was atypical for ransomware operations. In that incident, Process Watchdog was used to keep the GC2 process running. The content does not provide standalone GC2-specific hashes, but it does associate the tool with published file and network IOCs from the Fog ransomware investigation, including 66.112.216[.]232, amanda[.]protoflint[.]com, and 97.64.81[.]119.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Chinese state-sponsored hacking group APT41 was found abusing the GC2 (Google Command and Control) red teaming tool in data theft attacks against a Taiwanese media and an Italian job search company.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source pen-testing/post-exploitation tool referenced as being used alongside Syteca by Fog ransomware operators.
GC2 is an open-source post-exploitation tool that enables remote command execution and file exfiltration via Google Sheets or Microsoft SharePoint. It is typically used for discovery and C2 operations and is notable for its stealthy use of legitimate cloud services for communication.
An open-source Go-based command-and-control tool designed for red teaming. It uses Google services for C2, with agents connecting to Google Sheets to receive commands and using Google Drive to download payloads or exfiltrate stolen data.
Open source penetration testing tool used for command execution and data exfiltration via cloud services. Previously used by APT41 and now observed in ransomware operations for initial access and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.