SHEETCORD is a Go-based backdoor associated with an espionage campaign attributed with moderate confidence to APT36, also known as Transparent Tribe. It has been used against telecom, government, defense, energy, and other critical infrastructure organizations in South Asia, including activity involving Afghan telecom-themed lures and impersonation of Indian government entities.
The malware uses Google Sheets as a covert command-and-control channel, allowing operators to blend malicious traffic with legitimate cloud service activity. It supports remote command execution and is reported to execute commands through PowerShell. SHEETCORD gathers basic host information from compromised systems and creates per-victim spreadsheet tabs for bidirectional tasking and response.
For persistence, SHEETCORD establishes autorun execution and also hijacks browser shortcuts so the malware launches before the legitimate browser while still opening the expected browser to reduce user suspicion. This browser-hijacking mechanism extends beyond the browsers targeted by PATCHCORD and includes Chrome, Firefox, Edge, Brave, Opera, and Vivaldi. The malware has been described as building on capabilities seen in PATCHCORD and earlier Google Sheets-based tooling, representing an evolution toward Go-based implants and cloud-backed C2 tradecraft.
Observed delivery involved fake software installers and domains impersonating trusted organizations, including an India National Informatics Centre-themed lure. The broader campaign has been characterized as ongoing and focused on espionage-oriented access and control rather than disruptive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A more evolved implant, SHEETCORD, written in Go, has also been identified, which abuses Google Sheets for C2 communication, making malicious traffic harder to detect.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
SHEETCORD, a Go-based implant... abusing Google Sheets for C2 communication... HACKERAI C2 Agent... replaces PATCHCORD's custom HTTP server and SHEETCORD's Google Sheets with GitHub Gists, using dedicated upload and download functions for both tasking and data exfiltration.
The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
PATCHCORD... support[s] five core capabilities... running arbitrary commands through a hidden shell... SHEETCORD... executes commands through powershell -Command with script block wrapping.
The backdoor implements a remote command execution capability through PowerShell instead of "cmd.exe"
SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... The implant generates a temporary VBScript (temp_update.vbs) that rewrites each shortcut... The script is then executed via wscript
registers with its C2 server ("46.30.188[.]13") to receive tasking commands... uses Google Sheets for command-and-control (C2) communications... uses GitHub Gists for C2
uses Google Sheets for command-and-control (C2) communications... uses the Google Sheets API for C2... uses GitHub Gists for C2
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A more evolved implant written in Go that uses Google Sheets for command-and-control communication to blend malicious traffic with legitimate-looking activity.
A Go-based implant that appears to evolve PATCHCORD tooling and abuses the Google Sheets API for command-and-control, creating a dedicated spreadsheet tab per victim. It includes remote command execution and uses PowerShell for command execution.
A named implant/backdoor in the same APT36-linked espionage campaign, using cloud-based command-and-control mechanisms.
A Go-based malware variant related to the same campaign that persists via browser shortcut hijacking and uses Google Sheets as its command-and-control channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.