Executive Summary
In September 2026, researchers identified a deceptive campaign targeting organizations in Myanmar using a fake GlobalProtect VPN installer. The attack begins with a spearphishing link leading to a Google Sites landing page. The payload, an unsigned MSI, installs a native 64-bit executable that performs environmental checks to ensure the victim's public IP is located in Myanmar before proceeding with its malicious routine.
The backdoor demonstrates sophisticated use of cloud infrastructure, leveraging a Cloudflare Workers configuration gate to retrieve Google service-account credentials. It then uses the Google Sheets API as a command-and-control (C2) channel, polling specific spreadsheet cells for tasks and updating others with victim metadata. This technique allows malicious traffic to blend in with legitimate HTTPS traffic to well-known cloud providers.
While the implementation resembles techniques used by actors like HoneyMyte (CoolClient) or UNC2814 (GRIDTIDE), the report does not confirm direct attribution due to differences in delivery and code execution chains. This campaign represents a significant threat to regional entities, particularly those relying on Palo Alto Networks solutions, as it effectively masquerades as trusted security software to bypass detection.
