Podlipodcast player Webplayer

CyberWire Daily

CyberWire Daily

A RAT in the spreadsheet. [Research Saturday]

CyberWire Daily · Aug 22, 2026 · 29:47

0:0029:47

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests.

The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access.

The research and executive brief can be found here:


⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation


Learn more about your ad choices. Visit megaphone.fm/adchoices

Episodes: CyberWire Daily

PodliGet the free Podli app
↓ App