As cited
Copy frozen at (site build).
threat intel
APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2
Zscaler ThreatLabz identified three backdoors, SHEETCREEP, FIREPOWER, and MAILCREEP, deployed in the Sheet Attack campaign targeting Indian government entities between November 2025 and January 2026. The backdoors abuse legitimate cloud services including Google Sheets, Firebase, and Microsoft Graph application programming interface (API) for command-and-control communications, and analysis reveals fingerprints suggesting the threat actors used generative artificial intelligence (AI) in malware development. ThreatLabz assesses with medium confidence that the campaign originates from either a new Pakistan-linked advanced persistent threat (APT) group or a subgroup of APT36, based on victimology, tooling overlap, infrastructure indicators, and phishing lure similarities, though concurrent operation with traditional APT36 activity and new tools suggest evolution or a closely aligned group.
Why it matters: Indian government entities targeted by these campaigns are exposed to multistage attacks using novel cloud-based C2 channels; security teams should implement detection for SHEETCREEP, FIREPOWER, and MAILCREEP, monitor for malicious Google Sheets and Firebase activity, and scrutinize PDFs with Download Document buttons from untrusted sources.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2
Zscaler ThreatLabz identified three backdoors, SHEETCREEP, FIREPOWER, and MAILCREEP, deployed in the Sheet Attack campaign targeting Indian government entities between November 2025 and January 2026. The backdoors abuse legitimate cloud services including Google Sheets, Firebase, and Microsoft Graph application programming interface (API) for command-and-control communications, and analysis reveals fingerprints suggesting the threat actors used generative artificial intelligence (AI) in malware development. ThreatLabz assesses with medium confidence that the campaign originates from either a new Pakistan-linked advanced persistent threat (APT) group or a subgroup of APT36, based on victimology, tooling overlap, infrastructure indicators, and phishing lure similarities, though concurrent operation with traditional APT36 activity and new tools suggest evolution or a closely aligned group.
Why it matters: Indian government entities targeted by these campaigns are exposed to multistage attacks using novel cloud-based C2 channels; security teams should implement detection for SHEETCREEP, FIREPOWER, and MAILCREEP, monitor for malicious Google Sheets and Firebase activity, and scrutinize PDFs with Download Document buttons from untrusted sources.
- Source published
- First seen by Cybersecurity Tracker