UNC2814 GRIDTIDE Backdoor — China-Nexus Telecom & Government Espionage Campaign Exploiting Google Sheets API for C2 — Threadlinqs Intelligence
As of 2026-05-30, UNC2814 GRIDTIDE Backdoor — China-Nexus Telecom & Government Espionage Campaign Exploiting Google Sheets API for C2 is a critical-severity apt threat attributed to UNC2814 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0195 · Severity: CRITICAL · Status: MONITORING · Category: APT
Attribution: UNC2814 · China · ESPIONAGE
China-nexus threat actor UNC2814 (Gallium) conducted a massive espionage campaign breaching 53 telecommunications and government organizations across 42 countries using the GRIDTIDE backdoor, a
UNC2814 is a suspected People's Republic of China (PRC)-nexus cyber espionage group tracked by Google Threat Intelligence Group (GTIG) since at least 2017. The group has a long history of targeting international governments and global telecommunications organizations across Africa, Asia, and the Americas.
The campaign's centerpiece is GRIDTIDE, a novel C-based backdoor that weaponizes the Google Sheets API as a high-availability command-and-control platform. Rather than using traditional C2 servers, GRIDTIDE treats Google Sheets spreadsheets as bidirectional communication channels, disguising malicious traffic as legitimate Google API calls. The backdoor uses a locally stored 16-byte AES-128 CBC cryptographic key file (xapt.cfg) to decrypt its Google Drive configuration, which contains the threat actor's service account credentials, spreadsheet IDs, and private keys.
GRIDTIDE's C2 protocol operates through a cell-based polling mechanism: cell A1 is monitored every second for attacker commands, cell V1 stores victim fingerprint data (username, endpoint name, OS details, local IP, working directory, language settings, timezone), and cells A2-An facilitate data transfer. The backdoor encodes all communications using URL-safe Base64 and transfers files in 45KB fragments. Upon initialization, GRIDTIDE sanitizes its operational spreadsheet by deleting the first 1,000 rows across columns A-Z using the batchClear method to erase prior activity traces. After 120 consecutive failed command polling attempts, GRIDTIDE implements anti-detection jitter by randomizing polling intervals to 5-10 minutes.
The malware binary is deployed as /var/tmp/xapt, deliberately named to masquerade as the legacy xapt Debian/Ubuntu package management utility. Initial execution uses the command 'nohup ./xapt' to ensure process persistence across session termination. For boot persistence, UNC2814 creates a systemd service at /etc/systemd/system/xapt.service that spawns new instances from /usr/sbin/xapt.
Lateral movement is achieved via SSH using compromised service accounts, supplemented by living-off-the-land binaries for reconnaissance and privilege escalation. UNC2814 also deploys SoftEther VPN Bridge to establish encrypted outbound connections to attacker-controlled infrastructure, with VPN configuration metadata indicating this specific infrastructure has been in use since July 2018.
The campaign's targeting is consistent with telecommunications espionage operations: UNC2814 targets systems containing personally identifiable information (full names, phone numbers, dates and places of birth, voter ID numbers, national ID numbers) to identify, track, and monitor persons of interest. Access to telecom infrastructure enables interception of call data records, SMS messages, and lawful interception systems.
As of February 18, 2026, GTIG confirmed 53 victims across 42 countries with suspected infections in at least 20 additional nations, making this one of the most far-reaching espionage campaigns encountered in recent years. Google's disruption actions included terminating all attacker-controlled Google Cloud Projects, disabling GRIDTIDE C2 infrastructure, revoking Google Sheets API access, sinkholing known domains, and issuing formal victim notifications. The campaign is distinct from the Salt Typhoon campaign, involving separate victims and tradecraft.
---
**Revalidated on 2026-03-12**
No substantive changes required to the current description. All technical details (GRIDTIDE C2 mechanics, xapt binary masquerading, cell-based polling protocol, AES-128 CBC key file, SoftEther VPN bridge, systemd persistence, 45KB file fragmentation, 120-attempt jitter threshold) are fully corroborated by the Google Cloud Blog primary source and independent reporting. One contextual enhancement could be added: noting that UNC2814/Gallium's operational history extends to at least 2012 per Brandefense and ESET tracking (predating the 2017 GTIG tracking start date in the
Weaknesses (CWE)
CWE-506, CWE-912
Target sectors: telecommunications, government, critical-infrastructure
Target regions: Africa, Asia, Americas, Europe, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1190, T1059, T1543, T1078, T1543, T1078, T1036, T1027, T1078, T1070