SYMBOLCOMMON_NAMEaka. SYNONYMS
win.unidentified_126 (Back to overview)

Unidentified 126 (GoogleSheets C2)


According to Malware INFO Research Team, the analyzed fake GlobalProtect MSI contains an unsigned native 64-bit Windows executable that acts as a backdoor with a Myanmar-specific activation guardrail, using a public IP geolocation service to check the target's country before proceeding. The malware is written as a native PE32+ x64 Windows GUI application and features a staged design that contacts a Cloudflare Worker configuration gate to receive Google service-account credentials and a spreadsheet identifier, which are then used to authenticate to Google's OAuth endpoint and establish a Google Sheets-based command and control channel. The sample demonstrates capabilities for reading, writing, and polling specific spreadsheet cells to exchange device identifiers, victim metadata, operator commands, and command output, with a static design for executing Windows shell commands and capturing output through a hidden child process. The C2 channel establishment and polling were observed in runtime evidence, but no actual operator tasking, command execution, or result submission was captured.

References
2026-09-02Malware INFOMalware INFO Research Team
Fake GlobalProtect MSI Targets Myanmar Using Cloudflare and Google Sheets as C2
Unidentified 126 (GoogleSheets C2)

There is no Yara-Signature yet.