

I was confused at first, thinking that somehow Sheets’ systems were compromised.
The C-based backdoor uses Google Sheets as its C2 platform, can execute shell commands, and can upload and download files.
Instead, Sheets is just the command and control relay.
Which is pretty weird, though.





The American way