SheetRAT is a modular .NET remote access trojan (RAT) for Windows. Public reporting cited here describes it as a previously unreported malware family first publicly analyzed by Breakglass Intelligence in March 2026, with multiple MalwareBazaar samples observed between March 29 and April 1, 2026. Observed samples were .NET Framework 4.0 binaries, and reporting states the malware is distributed openly as a GitHub builder kit with 32 plugin DLLs and configuration templates.
Reported command-and-control does not use Google Sheets despite the name; instead, SheetRAT uses Pinggy tunnel infrastructure, including subdomains matching *[.]a[.]free[.]pinggy[.]link on arbitrary ports, allowing C2 traffic to blend with legitimate encrypted traffic to pinggy.link infrastructure. Recovered artifacts included a version string 2.6.4, a dropped DLL name xdwd.dll, an external IP discovery URL hxxps://api64[.]ipify[.]org/, and masquerade filenames such as Google SketchUp Update.exe, OBS Studio.exe, and RuntimeBroker.exe.
Capabilities described in the reporting include remote desktop control, webcam/camera access, microphone capture, keylogging, screenshots, clipboard monitoring, credential theft, file management, shell access, registry and service manipulation, scheduled tasks, autorun, SMB worming, file binding propagation, Monero and Ethereum Classic mining, DDoS, reverse proxying, geolocation, UAC bypass, and system disabling. Persistence mechanisms mentioned include HKCU and HKLM Run keys, scheduled tasks, Startup folder placement, Winlogon Userinit hijacking, AppInit_DLLs injection, and registry-based persistence.
Defense evasion and anti-analysis features directly mentioned include AMSI and ETW bypass, Windows Defender exclusion via WMI MSFT_MpPreference ExclusionPath modification, WMI-based virtual machine detection, sandbox DLL checks, process killing, masquerading, ConfuserEx-style obfuscation, and per-build monoalphabetic substitution obfuscation of strings. Reported sandbox/analysis-related DLL names include SbieDll.dll, snxhk.dll, cmdvrt32.dll, and Sf2.dll. Reported process kill targets include taskmgr.exe, ProcessHacker.exe, and procexp.exe. The malware also reportedly forges its PE compilation timestamp to 2100-10-13.
Operational context in the reporting links SheetRAT to malicious infrastructure that also supported Nexus Android banking trojan activity, phishing kits, and a crypto drainer. MalwareBazaar reportedly hosted more than 10 SheetRAT samples associated with that infrastructure. Another report linked SheetRAT sightings to infrastructure in AS202412 / OMEGATECH alongside multiple other malware families. Attribution remains low-to-medium confidence; embedded artifacts including the PDB path C:\Users\Malware\Desktop\hack tool\Backdoor\Sheet rat v 2.2\Src\Client\obj\Release\Client.pdb and Russian-language GitHub repository descriptions were assessed as suggesting a Russian-speaking developer or development community.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Multi-Layer Persistence : The builder can enable any combination of five persistence mechanisms simultaneously: Registry Run keys (HKCU and HKLM) Scheduled tasks (OnLogon trigger + recurring interval)
Multi-Layer Persistence : The builder can enable any combination of five persistence mechanisms simultaneously... AppInit_DLLs registry injection
Multi-Layer Persistence : The builder can enable any combination of five persistence mechanisms simultaneously: Registry Run keys (HKCU and HKLM) Scheduled tasks (OnLogon trigger + recurring interval)
Multi-Layer Persistence : The builder can enable any combination of five persistence mechanisms simultaneously... AppInit_DLLs registry injection
NONEUCLID RAT is equipped with features such as a rootkit, autoload functionality, and a User Account Control (UAC) bypass. These functionalities allow the malware to maintain persistence on infected systems and evade detection.
NONEUCLID RAT is equipped with features such as a rootkit, autoload functionality, and a User Account Control (UAC) bypass.
Additionally, NONEUCLID employs obfuscation techniques and anti-debugging mechanisms to make reverse engineering and analysis by security researchers more challenging.
Masquerading : Copies itself using legitimate-sounding filenames: Google SketchUp Update.exe , OBS Studio.exe , RuntimeBroker.exe
WMI-based virtual machine detection to avoid sandbox analysis
WMI-based virtual machine detection to avoid sandbox analysis
SheetRAT -- Windows RAT for desktop access, surveillance, and data exfiltration
Surveillance : ... Keylogger ... MITRE ATT&CK Coverage... Collection Keylogging T1056.001
Surveillance : ... Images (screenshot capture) ... MITRE ATT&CK Coverage... Collection Screen Capture T1113
Surveillance : ... Clipboard monitoring ... MITRE ATT&CK Coverage... Collection Clipboard Data T1115
When @Fact_Finder03 flagged 158.94.210[.]91 as a C2 panel... The /24 subnet surrounding that IP hosts 67 distinct command-and-control operations spanning 16 malware families.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan family identified as sharing the same bulletproof hosting subnet.
A .NET remote access trojan for Windows that includes AMSI and ETW bypasses, WMI-based VM detection, registry persistence, camera access, and obfuscation. It is described as being under active development and used for desktop access, surveillance, and data exfiltration.
A modular .NET remote access trojan/backdoor framework with a builder kit and 32 plugins. It uses Pinggy TCP tunnels for C2, obfuscates strings with a per-build monoalphabetic substitution cipher, supports credential theft, keylogging, screen/audio/video capture, file management, persistence, UAC bypass, sandbox evasion, process killing, lateral movement via SMB worming, crypto mining, DDoS, and reverse proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.