← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 22, 2026 · 07:00via The CyberWire

A RAT in the spreadsheet. [Research Saturday]

Brief

Today we are joined by Aaron Beardslee , Manager of Threat Research at Securonix , discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests.

The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access.

Read more on The CyberWire