SheetCreep is a Windows .NET/C# remote-access trojan associated with the Sheet Attack espionage activity and campaigns attributed with moderate confidence to Pakistan-aligned Transparent Tribe (APT36). It has targeted diplomatic organizations and Indian government- and military-related interests. The malware uses Google Sheets as a bidirectional command-and-control channel, creating victim-specific worksheet tabs, polling for encrypted tasking, executing commands through a hidden shell or in-process PowerShell, and returning encrypted command output through spreadsheet cells. SheetCreep encrypts configuration and command data, uses runtime string decryption, and can employ scheduled-task persistence. Observed variants conceal installed components using Windows file attributes and include anti-analysis behavior that reacts to selected debugging and network-analysis tools. Delivery has included phishing lures leading to malicious archives or disk-image files containing disguised Windows shortcuts; earlier activity also used document lures that redirected victims to gated download sites. SheetCreep loaders have used reflected .NET assembly loading to reduce straightforward payload visibility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In cases where it perhaps can't get away with cheap tactics like browser shortcut hijacking, Transparent Tribe can use Sheetcord, a Go-based evolution of Patchcord; and a remote access Trojan (RAT) called "Sheetcreep."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
For persistence, it installs a scheduled task named WindowsVaultSyncService with a misleading description crafted to appear harmless during manual review. The task runs at every user login with no time limit, keeping attacker access alive indefinitely.
Threat actors have upgraded their tools to make detection harder, replacing plaintext configuration settings with XOR-encrypted strings decoded only at runtime.
Victims receive an ISO file, and inside it is a shortcut that looks like a PDF... The malware also hides its executable using Hidden and System file attributes inside a directory path that closely resembles a standard Windows system folder.
Mutex Global\WinSync_<username>-<hostname>-<4char-hash> Mutex used by the RAT to enforce single-instance execution
Among the active victim tabs, the team identified 17 potential real targets with physical hardware and no sandbox indicators.
Использование Web Protocols через HTTPS к Google Sheets и Firebase; GOSHELL использует HTTP/S, а C2 применяет Google Sheets, Firebase и приватные GitHub-репозитории.
C2-инфраструктура эксплуатирует легитимные облачные сервисы: Google Sheets, Firebase и приватные GitHub-репозитории; также упомянуты Slack, Discord и Supabase.
SheetCreep... converts a Google Drive spreadsheet into a live control hub, polling it for encrypted instructions and writing encrypted responses back into cells.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Компонент вредоносного набора vibeware APT36; назначение в материале не уточняется.
A remote access trojan in Transparent Tribe's toolset mentioned alongside Sheetcord as part of the campaign against targets in Afghanistan and India.
A RAT referenced as prior tooling whose functionality overlaps with SHEETCORD.
A malware family referenced as contributing functionality to SHEETCORD.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.