A malicious MSI installer impersonating Palo Alto Networks GlobalProtect has targeted users in Myanmar, using trusted Cloudflare infrastructure and Google Sheets to support command-and-control (C2) activity. The campaign abuses the legitimacy and availability of these cloud services to blend malicious communications with ordinary web traffic and complicate network-based detection.
The installer’s operation is associated with Windows DLL-loading behavior, a common avenue for malware to execute malicious libraries through trusted applications or search-order weaknesses. Organizations with Myanmar-facing personnel should validate GlobalProtect installers against official sources and signatures, monitor endpoint installation activity, and investigate unexpected Cloudflare- or Google Sheets-related connections originating from VPN-client or installer processes.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 references tracked. Mallory keeps watching after this page renders.
malwareinfo.app
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.