Episode

A RAT in the spreadsheet. [Research Saturday]

Podcast
CyberWire Daily
Published
Aug 22, 2026
Duration seconds
1787
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/438/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW2337940270.mp3
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/a-rat-in-the-spreadsheet-research-saturday
Markdown
/podcast/cyberwire-daily-454880/a-rat-in-the-spreadsheet-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/a-rat-in-the-spreadsheet-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/a-rat-in-the-spreadsheet-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: ⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation