SHEETCREEP is a Windows backdoor and remote access trojan associated with espionage activity targeting Indian government, military, diplomatic, and other South Asian organizations, with some reporting also noting targeting of diplomatic entities and telecom-related victims. It has been linked with moderate confidence to APT36, also known as Transparent Tribe, and appears in broader campaigns that heavily abuse legitimate cloud platforms for command and control to blend into normal enterprise traffic.
SHEETCREEP is primarily documented as a small C#/.NET backdoor, although later reporting notes related Go-based tooling that appears to evolve or borrow functionality from SHEETCREEP. Its defining characteristic is the use of Google Sheets as a covert command-and-control channel. The malware authenticates to Google APIs using embedded cloud credentials, creates or uses victim-specific spreadsheet tabs, polls cells for encrypted tasking, and writes encrypted command output back into the sheet. Observed implementations encode data with Base64 and use encrypted configuration and command data, including variants using TripleDES and others using XOR-obfuscated runtime-decoded strings.
The malware supports remote command execution and interactive backdoor behavior. Reported variants execute commands through a hidden command shell or invoke PowerShell in-process to reduce child-process visibility. Some samples maintain a tight polling loop for near-real-time tasking. The malware also fingerprints infected hosts using identifiers derived from system and user information and uses those identifiers to organize victim-specific control channels.
Persistence has been achieved through scheduled tasks and, in related evolutions, startup or Run-key mechanisms. Defense-evasion measures include disguising payloads within seemingly benign files, reflective loading, hiding files with system and hidden attributes, runtime decryption of configuration, and anti-analysis checks that can trigger immediate system restart when analysis tools are detected. Delivery has been observed through phishing campaigns using themed lure documents and archives, including ISO or ZIP containers with malicious shortcut files that launch droppers or PowerShell-based loaders.
SHEETCREEP is part of a broader cluster of cloud-abusing implants that includes related families using Firebase, GitHub, and other trusted services for command and control and exfiltration. Its tradecraft reflects an emphasis on low-cost, rapidly adaptable espionage tooling that leverages legitimate web services to complicate detection and attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Go-based malware combines functionality previously observed in the SHEETCREEP RAT with several capabilities introduced in PATCHCORD, suggesting an evolution of the operator's tooling.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
For persistence, it installs a scheduled task named WindowsVaultSyncService with a misleading description crafted to appear harmless during manual review. The task runs at every user login with no time limit, keeping attacker access alive indefinitely.
Threat actors have upgraded their tools to make detection harder, replacing plaintext configuration settings with XOR-encrypted strings decoded only at runtime.
Victims receive an ISO file, and inside it is a shortcut that looks like a PDF... The malware also hides its executable using Hidden and System file attributes inside a directory path that closely resembles a standard Windows system folder.
Mutex Global\WinSync_<username>-<hostname>-<4char-hash> Mutex used by the RAT to enforce single-instance execution
Among the active victim tabs, the team identified 17 potential real targets with physical hardware and no sandbox indicators.
All communication runs through the Google Sheets API over HTTPS, making the traffic look identical to normal Google Workspace activity.
SheetCreep... converts a Google Drive spreadsheet into a live control hub, polling it for encrypted instructions and writing encrypted responses back into cells.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT referenced as prior tooling whose functionality overlaps with SHEETCORD.
A previously documented RAT referenced as functionally overlapping with SHEETCORD, notably for Google Sheets-based C2 using hardcoded GCP service-account credentials and per-victim spreadsheet tabs.
A C# remote access trojan used in an espionage campaign targeting diplomatic organizations. It is delivered via phishing with an ISO lure, persists via a scheduled task, executes commands including in-process PowerShell, collects data, and uses the Google Sheets API over HTTPS as its command-and-control channel while hiding configuration with XOR-encrypted strings.
A C# backdoor that uses a Google Sheets/Drive spreadsheet as a C2 control hub by polling for encrypted commands and writing encrypted responses back into spreadsheet cells.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.