Episode
A RAT in the spreadsheet. [Research Saturday]
- Podcast
- CyberWire Daily
- Published
- Aug 22, 2026
- Duration seconds
- 1787
- Processing state
not_requested- Canonical source
- https://thecyberwire.com/podcasts/research-saturday/438/notes
Actions
POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/a-rat-in-the-spreadsheet-research-saturday/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/cyberwire-daily-454880/a-rat-in-the-spreadsheet-research-saturday.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation