Fake GlobalProtect MSI Targets Myanmar via Google Sheets
Score: 9/10

Fake GlobalProtect MSI Targets Myanmar via Google Sheets

An unsigned GlobalProtect-themed MSI deploys a backdoor that utilizes Cloudflare Workers for configuration and Google Sheets for C2 communication, specifically targeting victims in Myanmar.

Executive Summary

In September 2026, researchers identified a deceptive campaign targeting organizations in Myanmar using a fake GlobalProtect VPN installer. The attack begins with a spearphishing link leading to a Google Sites landing page. The payload, an unsigned MSI, installs a native 64-bit executable that performs environmental checks to ensure the victim's public IP is located in Myanmar before proceeding with its malicious routine.

The backdoor demonstrates sophisticated use of cloud infrastructure, leveraging a Cloudflare Workers configuration gate to retrieve Google service-account credentials. It then uses the Google Sheets API as a command-and-control (C2) channel, polling specific spreadsheet cells for tasks and updating others with victim metadata. This technique allows malicious traffic to blend in with legitimate HTTPS traffic to well-known cloud providers.

While the implementation resembles techniques used by actors like HoneyMyte (CoolClient) or UNC2814 (GRIDTIDE), the report does not confirm direct attribution due to differences in delivery and code execution chains. This campaign represents a significant threat to regional entities, particularly those relying on Palo Alto Networks solutions, as it effectively masquerades as trusted security software to bypass detection.

Key Details

Threat Name

Fake GlobalProtect Myanmar Google Sheets C2

Affects

—

Adversary

HoneyMyte Other Adversaries and Aliases: UNC2814

Malware/Tools

CoolClient, Voldemort, SHEETCREEP, SheetAgent, GRIDTIDE, PlugX

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance8
Clarity & Structure9
Technical Depth10

Sources