Google Takes Down Telecom Hackers Using Sheets and SaaS Apps to Spread Mayhem

Google Takes Down Telecom Hackers Using Sheets and SaaS Apps to Spread Mayhem

Google Takes Down Telecom Hackers Using Sheets and SaaS Apps to Spread Mayhem

A decade-old threat actor is up to some new shenanigans.

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

(Image credit: Shutterstock)

Copy link

Facebook

X

Whatsapp

Reddit

Pinterest

Flipboard

Threads

Email

Share this article

0

Join the conversation

Follow us

Add us as a preferred source on Google

Newsletter

Get the TechRadar Newsletter

Sign up for breaking news, reviews, opinion, top tech deals, and more.

Contact me with news and offers from other Future brands

Receive email from us on behalf of our trusted partners or sponsors

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

You are now subscribed

Your newsletter sign-up was successful

An account already exists for this email address, please log in.

Subscribe to our newsletter

Google, Mandiant, and partners disrupted UNC2814 espionage campaign

Group used GridTide backdoor leveraging Google Sheets API for C2

Operation hit 53 organizations in 42 countries since 2023; attacker infrastructure and accounts disabled

Google has managed to take down a global espionage network which targeted government and telecom organizations in more than 40 countries around the world.

In a new research report, Google said that its Threat Intelligence Group (GTIG), together with Mandiant and other partners discovered a Chinese state-affiliated threat actor tracked as UNC2814 running a new spy campaign.

In this newest campaign, the group was deploying a previously unseen backdoor malware called GridTide, which leveraged the Google Sheets API for C2 infrastructure.

Instead of connecting to a remote server somewhere to receive instructions and exfiltrate data, the backdoor makes HTTPS requests to legitimate Google infrastructure, blending with normal enterprise traffic and thus not raising any alarms.

You may like

‘We believe our actions have seriously impacted one of the largest residential proxy providers’: Google takes the fight to IPIDEA and removes millions of devices from criminal network

AI malware, Gemini lures and more: Google reveals how hackers are actually using AI

Yet another phishing campaign impersonates trusted Google services – here’s what we know

Disrupting the attackers

All of the commands are stored in a spreadsheet cell of a document belonging to the attackers.

The operators insert encoded instructions into specific rows or cells, and the malware then periodically checks, decodes, and executes them.

In some cases, exfiltrated data can also be written back into the sheet – however, GTIG said it did not observe any instances of data exfiltration.

UNC2814 is a relatively known threat actor, with reports of its activity dating back to 2017 and possibly before.

The campaign started in 2023 and affected at least 53 organizations in 42 countries.

Google suspects that UNC2814 is present in at least 20 more countries.

Most of Latin America, Eastern Europe, Russia, parts of Africa and parts of South Asia seem to have been hit.

With the exception of Portugal, Western Europe is mostly unscathed.

The US was not touched, as well.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brands

Receive email from us on behalf of our trusted partners or sponsors

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

As part of the disruption efforts, Google terminated all Google Cloud Projects the attackers controlled, severing their persistent access to environments compromised by GridTide.

They identified and disabled all known UNC2814 infrastructure, disabled attacker accounts, and revoked access to the Google Sheets API calls.

Finally, it released a set of IoCs linked to UNC2814 infrastructure active since at least 2023.

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Read our full guide to the best antivirus

1. Best overall:Bitdefender Total Security

2. Best for families:Norton 360 with LifeLock

3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Sead Fadilpašić

Social Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina.

He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations).

In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans.

He’s also held several modules on content writing for Represent Communications.

View More

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout

Read more