SHEETCORD is a Go-based implant used in a South Asia-focused espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked threat actor. It represents an evolution of the operator’s tooling from earlier custom backdoors toward cloud-backed command-and-control, combining functionality associated with related malware families such as PATCHCORD and HACKERAI C2 Agent.
SHEETCORD is designed for covert remote access and post-compromise control on Windows systems. It executes attacker-supplied commands through PowerShell, performs host interaction consistent with backdoor activity, and establishes persistence through both a Run key and a Startup-folder script. It also reimplements browser shortcut hijacking previously seen in related tooling, allowing the malware to launch before the legitimate browser while preserving normal user experience to reduce suspicion. Its browser targeting extends across Chrome, Firefox, Edge, Brave, Opera, and Vivaldi.
A defining feature of SHEETCORD is its abuse of Google Sheets as a bidirectional command-and-control channel. The implant uses the Google Sheets API to create per-victim spreadsheet tabs and exchange tasking and results through that cloud service, helping the operator blend malicious traffic with legitimate web activity and reduce reliance on conventional attacker-hosted infrastructure.
SHEETCORD has been delivered through themed fake software installers and impersonation lures associated with telecom and government-related entities. Campaign targeting has included Afghan telecom providers as well as government, defense, energy, and broader critical infrastructure organizations in South Asia. The malware’s role in that activity is consistent with long-term espionage and covert access rather than disruptive or destructive operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
SHEETCORD, a Go-based implant... abusing Google Sheets for C2 communication... HACKERAI C2 Agent... replaces PATCHCORD's custom HTTP server and SHEETCORD's Google Sheets with GitHub Gists, using dedicated upload and download functions for both tasking and data exfiltration.
The implant implements a remote command execution capability main.executeShellCommand similar to PATCHCORD. However, instead of invoking cmd.exe /c, it executes commands through powershell -Command with script block wrapping.
SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... The implant generates a temporary VBScript (temp_update.vbs) that rewrites each shortcut... The script is then executed via wscript
If not found, it writes its own executable path to this key, establishing persistence across reboots... SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... It then adds a registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
If not found, it writes its own executable path to this key, establishing persistence across reboots... SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... It then adds a registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
The threat actor deployed PATCHCORD, SHEETCORD, and HACKERAI C2 Agent, transitioning from a custom C/C++ backdoor to Go-based implants that abuse Google Sheets and GitHub Gists for covert command-and-control.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named implant/backdoor in the same APT36-linked espionage campaign, using cloud-based command-and-control mechanisms.
A Go-based malware variant related to the same campaign that persists via browser shortcut hijacking and uses Google Sheets as its command-and-control channel.
A Go-based implant/RAT that evolves PATCHCORD functionality, using Google Sheets API v4 and hardcoded GCP service-account credentials for C2. It supports remote command execution, host info collection, persistence via Startup VBScript and Run key, and browser shortcut hijacking across multiple browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.