SHEET#CREEP Campaign: APT36 Abuses Google Sheets API
Score: 9/10

SHEET#CREEP Campaign: APT36 Abuses Google Sheets API

The Pakistan-aligned APT36 is deploying a new variant of the SHEETCREEP RAT using Google Sheets for C2 communication, targeting Indian diplomatic interests.

Executive Summary

Securonix Threat Research has identified an ongoing espionage campaign dubbed SHEET#CREEP, attributed with moderate confidence to the Pakistan-aligned actor APT36 (Transparent Tribe). The campaign utilizes a diplomatic-themed ISO phishing lure, specifically referencing the "UAE-India Strategic Partnership Week," to deliver a multi-stage C# Remote Access Trojan (RAT).

The evolved SHEETCREEP malware now includes XOR-obfuscated configuration strings and abuses the Google Sheets API as a bidirectional command-and-control (C2) channel. By utilizing legitimate Google Cloud Platform (GCP) infrastructure, the actor effectively blends malicious traffic with normal business communications. Analysts identified over 90 active victim tabs on a single C2 spreadsheet, including a high-confidence target in Islamabad, Pakistan, suggesting the group targets diplomatic and government entities.

This campaign represents a significant risk due to its high level of operational security, including in-process PowerShell execution to evade EDR and the use of legitimate cloud services to bypass network-level defenses.

Key Details

Threat Name

SHEETCREEP

Affects

—

Adversary

APT36

Malware/Tools

SHEETCREEP

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance8
Enterprise Relevance9
Clarity & Structure10
Technical Depth9

Sources