MAILCREEP is a Golang backdoor observed by Zscaler ThreatLabz as second-stage tooling in the “Sheet Attack” campaign. It checks network connectivity by connecting to 8.8.8.8:53, then uses Microsoft Graph API within a threat actor-controlled Azure tenant to implement email/folder-based command-and-control (C2). MAILCREEP decrypts Base64-encoded content using AES-256-CBC and executes received commands via cmd.exe /c. The campaign context indicates targeting focused on Windows systems in India and, more broadly, Indian government entities; ThreatLabz attributed the broader activity with medium confidence to a Pakistan-linked actor (possibly a new subgroup or an APT36 faction). No additional high-confidence infection vector details or specific MAILCREEP indicators of compromise (e.g., hashes, domains, tenant IDs) are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Secondary tool in the 'Sheet Attack' campaign; described as supporting email/SMTP-based data exfiltration and post-compromise activity alongside other tooling.
Secondary tool in the Sheet Attack campaign associated with email/SMTP-based data exfiltration (and described as part of credential/lateral movement/persistence tooling).
Golang backdoor used as an additional payload. Checks connectivity by TCP connecting to 8.8.8.8:53, then uses Microsoft Graph API within an attacker-controlled Azure tenant for email-based C2: creates a per-victim mailbox folder, polls for emails with subjects starting 'Input', Base64-decodes and AES-256-CBC decrypts contents, parses CSV-formatted commands, and executes them via cmd.exe /c.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.