Executive Summary
Securonix Threat Research has identified an ongoing espionage campaign dubbed SHEET#CREEP, attributed with moderate confidence to the Pakistan-aligned actor APT36 (Transparent Tribe). The campaign utilizes a diplomatic-themed ISO phishing lure, specifically referencing the "UAE-India Strategic Partnership Week," to deliver a multi-stage C# Remote Access Trojan (RAT).
The evolved SHEETCREEP malware now includes XOR-obfuscated configuration strings and abuses the Google Sheets API as a bidirectional command-and-control (C2) channel. By utilizing legitimate Google Cloud Platform (GCP) infrastructure, the actor effectively blends malicious traffic with normal business communications. Analysts identified over 90 active victim tabs on a single C2 spreadsheet, including a high-confidence target in Islamabad, Pakistan, suggesting the group targets diplomatic and government entities.
This campaign represents a significant risk due to its high level of operational security, including in-process PowerShell execution to evade EDR and the use of legitimate cloud services to bypass network-level defenses.
