Last seven days
- First activity
- Sep 10, 2026
- Last activity
- Sep 10, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Samples
Reported operators
In this blog, we will walk through the complete technical analysis of the final payload which we named as SheetAgent RAT... The second file dropped by the .NET loader is agent.exe which we named as SheetAgent.
Reporting
Researchers reported a recruitment-themed malware campaign targeting Indian government job seekers with a fake Cabinet Secretariat notice for Senior Field Officer roles. The infection chain delivers a ZIP archive containing a malicious .lnk file, a PowerShell script, and a .NET executable that installs the legitimate ControlR remote management agent alongside a custom RAT called SheetAgent. The malware persists through a scheduled task or Startup-folder shortcut, disguises files with Windows-like names, and uses anti-VM, anti-sandbox, and self-cleanup checks to hinder analysis. Seqrite said SheetAgent uses hardcoded Google service account credentials to access Google Sheets and Google Drive, with an attacker-controlled sheet acting as a backup command-and-control and exfiltration channel. Investigators also linked infrastructure at 38.242.157.89 to the decoy PDF and several authenticated management panels, including SecureMonitor and PrivateRat. The tradecraft overlaps with earlier campaigns that used cloud services such as Google Sheets, Firebase, GitHub, and Microsoft Graph for covert C2 against Indian targets, and Seqrite attributed the operation to APT36 with medium confidence.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.