{"podcast":{"title":"CyberWire Daily","slug":"cyberwire-daily-454880","podcast_index_feed_id":454880,"rss_url":"https://feeds.megaphone.fm/cyberwire-daily-podcast","website_url":"https://thecyberwire.com/podcasts/daily-podcast","image_url":"https://megaphone.imgix.net/podcasts/58ab7ae0-def8-11ea-b34c-b35b208b0539/image/8676ed612d7a335a98a9173d70cb11be.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks, Inc.","episode_count":3765,"summary":"The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.","last_synced_at":"2026-09-23T20:18:19.501651+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880"},"episode":{"title":"A RAT in the spreadsheet. [Research Saturday]","slug":"a-rat-in-the-spreadsheet-research-saturday","published_at":"2026-08-22T07:00:00+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880/a-rat-in-the-spreadsheet-research-saturday","show_page_url":"https://stenobird.com/podcast/cyberwire-daily-454880","url":"https://thecyberwire.com/podcasts/research-saturday/438/notes","audio_url":"https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW2337940270.mp3","summary":"Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing \"Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation.\" Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: ⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation","meta_description":"Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing \"Analyzing SHEET#CREEP: SHEETCREEP is up again with different…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1787,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/a-rat-in-the-spreadsheet-research-saturday/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cyberwire-daily-454880/a-rat-in-the-spreadsheet-research-saturday.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}