CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6268

As cited

Copy frozen at (site build).

threat intel

APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2

Zscaler ThreatLabz identified three backdoors, SHEETCREEP, FIREPOWER, and MAILCREEP, deployed in the Sheet Attack campaign targeting Indian government entities between November 2025 and January 2026. The backdoors abuse legitimate cloud services including Google Sheets, Firebase, and Microsoft Graph application programming interface (API) for command-and-control communications, and analysis reveals fingerprints suggesting the threat actors used generative artificial intelligence (AI) in malware development. ThreatLabz assesses with medium confidence that the campaign originates from either a new Pakistan-linked advanced persistent threat (APT) group or a subgroup of APT36, based on victimology, tooling overlap, infrastructure indicators, and phishing lure similarities, though concurrent operation with traditional APT36 activity and new tools suggest evolution or a closely aligned group.

Why it matters: Indian government entities targeted by these campaigns are exposed to multistage attacks using novel cloud-based C2 channels; security teams should implement detection for SHEETCREEP, FIREPOWER, and MAILCREEP, monitor for malicious Google Sheets and Firebase activity, and scrutinize PDFs with Download Document buttons from untrusted sources.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP | Part 2

Zscaler ThreatLabz identified three backdoors, SHEETCREEP, FIREPOWER, and MAILCREEP, deployed in the Sheet Attack campaign targeting Indian government entities between November 2025 and January 2026. The backdoors abuse legitimate cloud services including Google Sheets, Firebase, and Microsoft Graph application programming interface (API) for command-and-control communications, and analysis reveals fingerprints suggesting the threat actors used generative artificial intelligence (AI) in malware development. ThreatLabz assesses with medium confidence that the campaign originates from either a new Pakistan-linked advanced persistent threat (APT) group or a subgroup of APT36, based on victimology, tooling overlap, infrastructure indicators, and phishing lure similarities, though concurrent operation with traditional APT36 activity and new tools suggest evolution or a closely aligned group.

Why it matters: Indian government entities targeted by these campaigns are exposed to multistage attacks using novel cloud-based C2 channels; security teams should implement detection for SHEETCREEP, FIREPOWER, and MAILCREEP, monitor for malicious Google Sheets and Firebase activity, and scrutinize PDFs with Download Document buttons from untrusted sources.

VendorsMicrosoftGoogleGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary