SHEETCORD is a Go-based backdoor associated with the Pakistan-linked espionage actor Transparent Tribe, also tracked as APT36. It appears to be an evolution of PATCHCORD and incorporates related functionality seen across the actor’s newer implant set. The malware has been used in campaigns targeting telecom, government, defense, energy, and other critical infrastructure organizations in South Asia, with especially notable targeting of Afghan telecom entities and Indian government-related organizations.
SHEETCORD uses Google Sheets as a covert command-and-control channel, allowing operators to blend malicious traffic with legitimate cloud-service activity. It supports remote command execution and gathers basic host information from compromised systems. Reported variants execute commands through PowerShell and create per-victim spreadsheet tabs for bidirectional tasking and response handling.
On Windows systems, SHEETCORD establishes persistence through startup-based mechanisms, including Windows startup registration and use of a Visual Basic Script placed for execution at user logon. It also reimplements browser shortcut hijacking techniques previously associated with PATCHCORD, extending this behavior beyond Chrome, Edge, and Firefox to additional Chromium-based browsers such as Brave, Opera, and Vivaldi. This approach allows the malware to launch before the legitimate browser while still opening the expected application to reduce user suspicion.
Observed delivery has involved impersonation infrastructure and themed installer lures, including domains masquerading as Indian government resources. The malware is part of a broader espionage toolchain that includes PATCHCORD, SHEETCREEP, and HACKERAI C2 Agent, reflecting Transparent Tribe’s shift toward Go-based implants and abuse of trusted cloud platforms for command-and-control. Its operational role is consistent with long-term access, covert tasking, and post-compromise control in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In cases where it perhaps can't get away with cheap tactics like browser shortcut hijacking, Transparent Tribe can use Sheetcord, a Go-based evolution of Patchcord; and a remote access Trojan (RAT) called "Sheetcreep."
In cases where it perhaps can't get away with cheap tactics like browser shortcut hijacking, Transparent Tribe can use Sheetcord, a Go-based evolution of Patchcord; and a remote access Trojan (RAT) called "Sheetcreep."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
SHEETCORD, a Go-based implant... abusing Google Sheets for C2 communication... HACKERAI C2 Agent... replaces PATCHCORD's custom HTTP server and SHEETCORD's Google Sheets with GitHub Gists, using dedicated upload and download functions for both tasking and data exfiltration.
Its phishing lures have impersonated network and logistics tools used by a large Afghani telecommunications company, a fuel-conservation tool for India's energy sector, an Indian government employee benefits resource, and so on.
PATCHCORD... support[s] five core capabilities... running arbitrary commands through a hidden shell... SHEETCORD... executes commands through powershell -Command with script block wrapping.
The backdoor implements a remote command execution capability through PowerShell instead of "cmd.exe"
SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... The implant generates a temporary VBScript (temp_update.vbs) that rewrites each shortcut... The script is then executed via wscript
Sheetcord uses the more conventional persistence tactic of registering itself as a Windows startup process, and tries to conceal its C2 traffic by sending it through Google Sheets.
uses Google Sheets for command-and-control (C2) communications... uses the Google Sheets API for C2... uses GitHub Gists for C2
Sheetcord uses the more conventional persistence tactic of registering itself as a Windows startup process, and tries to conceal its C2 traffic by sending it through Google Sheets.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based evolution of Patchcord used by Transparent Tribe. It uses Windows startup persistence and conceals command-and-control traffic through Google Sheets.
A more evolved implant written in Go that uses Google Sheets for command-and-control communication to blend malicious traffic with legitimate-looking activity.
A Go-based implant that appears to evolve PATCHCORD tooling and abuses the Google Sheets API for command-and-control, creating a dedicated spreadsheet tab per victim. It includes remote command execution and uses PowerShell for command execution.
A named implant/backdoor in the same APT36-linked espionage campaign, using cloud-based command-and-control mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.