Skip to content

Observed infrastructure

Last seven days

First activity
Sep 10, 2026
Last activity
Sep 10, 2026
Feed role
Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • FR1

Leading providers

  • Contabo GmbH1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Transparent Tribe

In this blog, we will walk through the complete technical analysis of the final payload which we named as SheetAgent RAT... The second file dropped by the .NET loader is agent.exe which we named as SheetAgent.

Reporting

Research mentioning SheetAgent

Jul 14
Malware News

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers - Malware News - Malware Analysis, News and Indicators

Researchers reported a recruitment-themed malware campaign targeting Indian government job seekers with a fake Cabinet Secretariat notice for Senior Field Officer roles. The infection chain delivers a ZIP archive containing a malicious .lnk file, a PowerShell script, and a .NET executable that installs the legitimate ControlR remote management agent alongside a custom RAT called SheetAgent. The malware persists through a scheduled task or Startup-folder shortcut, disguises files with Windows-like names, and uses anti-VM, anti-sandbox, and self-cleanup checks to hinder analysis. Seqrite said SheetAgent uses hardcoded Google service account credentials to access Google Sheets and Google Drive, with an attacker-controlled sheet acting as a backup command-and-control and exfiltration channel. Investigators also linked infrastructure at 38.242.157.89 to the decoy PDF and several authenticated management panels, including SecureMonitor and PrivateRat. The tradecraft overlaps with earlier campaigns that used cloud services such as Google Sheets, Firebase, GitHub, and Microsoft Graph for covert C2 against Indian targets, and Seqrite attributed the operation to APT36 with medium confidence.

Jul 14
Seqrite

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers | Seqrite

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.