GRIDTIDE is a custom C-based Linux backdoor used by the suspected PRC-nexus cyberespionage group UNC2814. It uses legitimate Google Sheets API operations as its command-and-control channel, allowing tasking and data transfer to blend with ordinary SaaS traffic. The backdoor decrypts configuration containing Google service-account authentication material and a spreadsheet identifier, clears a predefined spreadsheet range on startup, fingerprints the compromised host, and exchanges commands, status, and data through designated spreadsheet cells. GRIDTIDE can execute arbitrary shell commands and upload or download files. It collects host and environment details including the username, hostname, operating-system information, local network address, locale, and time zone; its C2 data uses URL-safe Base64 encoding. UNC2814 used GRIDTIDE against telecommunications and government entities internationally, including systems containing sensitive personally identifiable information. The broader intrusion activity included systemd-based persistence, SSH-enabled lateral movement, living-off-the-land tooling, and SoftEther VPN Bridge tunnels. No direct data exfiltration was observed in the reported campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2814 used a custom C-based backdoor, GRIDTIDE, that abuses legitimate Google Sheets API calls for command-and-control (C2) to run commands, move files, and fingerprint endpoints while blending into normal SaaS traffic.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
GRIDTIDE [is] embedded with an encrypted configuration... T1027 – Obfuscated Files or Information: Obfuscates code, scripts, or configuration to evade detection.
Makes files, processes, or services appear legitimate through naming and metadata.
Injects code into other processes to run with higher privileges or evade detection.
Decodes or unpacks payloads at runtime to hinder static analysis.
Detects or evades virtualized and sandboxed analysis environments.
Enumerates network interfaces, routes, and DNS settings.
Tests outbound connectivity and available egress paths.
GRIDTIDE... collected username, hostname, operating system, IP address, locale, and timezone.
Lists active network connections to identify services and peers.
GRIDTIDE... collected username, hostname, operating system, IP address, locale, and timezone.
Searches the filesystem for interesting data or locations.
It fingerprints the endpoint by collecting... language settings, and local time zone.
This activity is not the result of a security vulnerability in Google’s products; rather, it abuses legitimate Google Sheets API functionality to disguise C2 traffic. | The attacker was using API calls to communicate with SaaS apps as command-and-control (C2) infrastructure to disguise their malicious traffic as benign... GRIDTIDE leverages Google Sheets as a high-availability C2 platform.
GRIDTIDE abuses legitimate Google Sheets API calls for command-and-control (C2)... while blending into normal SaaS traffic.
GRIDTIDE polls a specific Google Sheet cell... via API for attacker commands, then uses predefined cells to handle tasking, status updates, and data exfiltration.
http://130.94.6.228/apt.tar.gz ... Contained GRIDTIDE; additional archives contained SoftEtherVPN Bridge components.
To evade detection and web filtering, GRIDTIDE employs a URL-safe Base64 encoding scheme for all data sent and received.
245 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Google Sheets APIをC2チャネルとして悪用し、被害端末からホスト情報を収集し、スプレッドシート経由でコマンド受信・実行結果送信を行うマルウェアとして説明されている。本文では、Google Sheets上のセルを使ってコマンド、出力、ホスト情報をやり取りし、SaaS C2/LoTSの一例として扱われている。
Backdoor that uses Google Sheets API as a command-and-control channel to blend in with trusted cloud traffic and enable data transfer and remote command execution.
Backdoor used for cyber-espionage that leverages Google Sheets API as a covert command-and-control channel to blend in with trusted Google service traffic and enable data transfer and remote command execution.
Backdoor used in a China-linked cyberespionage campaign; noted for cloud-based API abuse for covert command-and-control and surveillance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.