Threat reportMalwareTL-2026-2368
Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2
Fake GlobalProtect MSI Targets Myanmar Using Cloudflare (TL-2026-2368), also tracked as win.unidentified_126, is a high-severity malware campaign, first published 2026-09-07. It has no confirmed attribution, affects Palo Alto Networks GlobalProtect, maps to 9 MITRE ATT&CK techniques (T1036, T1053, T1059), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-2368
- Threat ID
- TL-2026-2368
- Also known as
- win.unidentified_126
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration
- Target regions
- myanmar, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Fake GlobalProtect MSI Targets Myanmar Using Cloudflare
Malware and tooling: cmd - S0106
How Fake GlobalProtect MSI Targets Myanmar Using Cloudflare works
An unsigned MSI masquerading as Palo Alto Networks GlobalProtect VPN delivers a staged backdoor targeting Myanmar. The malware uses a geolocation check (ip-api.com) to restrict execution to Myanmar, then establishes a Cloudflare Workers config gate for credential retrieval followed by Google Sheets API for command-and-control. The sample could not be attributed to any known threat actor and is cataloged under Malpedia family win.unidentified_126.
On 2026-09-02, the Malware INFO Research Team published an analysis of a malicious MSI installer masquerading as Palo Alto Networks GlobalProtect VPN (version 11.5.0, manufacturer 'PaloAlto') targeting users in Myanmar. The delivery chain begins with a spearphishing email containing a link to a Google Sites landing page, which serves the malicious MSI.
Delivery and Initial Execution
The MSI (GlobalProtect.msi, 3,475,968 bytes, SHA-256 a124caa58d956c7430ecb8772a3794266235917670c5b56564342bd1456897e7) is unsigned and forges its metadata to impersonate a legitimate Palo Alto Networks installer. It installs to C:\Program Files\PaloAlto\GlobalProtect VPN\ with ALLUSERS=2 (per-machine). The installer action GlobalProtect.exe /Install launches the embedded payload executable (GlobalProtect.exe, 425,984 bytes, SHA-256 33d696728101c9caf6ebb215ba176bbb94e5cc16218b574029b622fd6e3bee8c, PE32+ x64 Windows GUI, unsigned). The MSI drops and locally loads bcrypt.dll (valid Microsoft-signed), CRYPT32.dll (valid Microsoft-signed), and a trojanized WININET.dll (5,039,616 bytes, unsigned) into the app directory, exhibiting DLL binary-planting behavior.
Configuration Decryption
The embedded GlobalProtect.exe decrypts its configuration blobs using AES-256-CBC with a key derived from SHA-256('AmountOfFreeDiskSpace'), a form of environmental keying. The IV is the first 16 bytes of each blob. Decryption recovers: the geolocation host (ip-api.com), the installation directory, the Cloudflare Workers gate URL, the gate header name (X-Bot-Secret), and the Windows command-shell prefix.
Geolocation Execution Guardrail
Upon execution, the malware sends a GET /json request to ip-api.com (port 80) with the custom user-agent 'SheetsBot/1.0'. The response containing country: Myanmar, countryCode: MM is verified before proceeding. This geolocation gate restricts execution to Myanmar-based victims. The full process lifetime for this check was approximately 2.86 seconds, after which the process exited with status 0.
Cloudflare Workers Config Gate
After passing the geolocation check, the malware contacts a Cloudflare Workers endpoint at https://sheets-config-gate.hewlett-pack{1..9}.workers.dev/config0, sending the X-Bot-Secret header. Only hewlett-pack1 was observed in DNS; hosts 2-9 existed only in writable private memory. The config gate response (observed via InternetReadFile in the debugger) returns: google_creds, spreadsheet_id, project_id, private_key_id, private_key, client_email, and client_id. BeaconBeagle query returned no match for the workers.dev domain.
Google Cloud OAuth and Sheets API C2
Using the recovered credentials (project elliptical-tree-505904-p7, client ID 101714939433347726433), the malware constructs a JWT with RS256 signature, claims aud=https://oauth2.googleapis.com/token, scope=https://www.googleapis.com/auth/spreadsheets, and a 3,600-second expiry. A successful OAuth token exchange is observed, followed by Google Sheets API operations. The C2 protocol uses four fixed columns: Sheet1!A for victim device identification (val- marker, scanned rows 1-100), Sheet1!B for public IP/victim metadata, Sheet1!C for operator command queue (command- marker, polled but no command observed), and Sheet1!D for command output (out- marker, not observed). Commands are designed to execute via a hidden cmd.exe child process (CREATE_NO_WINDOW) with inherited stdout/stderr pipes.
Persistence
The malware establishes persistence through two mechanisms: GlobalProtectVPN RunOnce values under both HKCU and HKLM registry hives, and a scheduled task named GlobalProtectVPNUpdate with PaloAlto-themed metadata referencing GlobalProtect.exe.
Attribution
The Malware INFO Research Team explicitly states: 'We found no evidence sufficient to identify this sample as CoolClient, connect it to HoneyMyte, or attribute it to another named actor.' The Malpedia entry catalogs the sample under the temporary family designation win.unidentified_126. The Kaspersky HoneyMyte/CoolClient report (August 2026) is noted as regional context only — that chain used PlugX, DLL sideloading via a legitimate Sangfor application, synchost.exe injection, and a kernel rootkit, none of which overlap with this sample.
Related Sheets-C2 Ecosystem
This campaign joins a growing ecosystem of malware families abusing Google Sheets as a C2 channel, each with distinct operational patterns: Voldemort (Proofpoint, August 2024) — a China-aligned TA415/APT41 campaign using individual spreadsheet tabs per victim with file exchange commands; SHEETCREEP (Zscaler, January 2026) — a Pakistan-linked APT36 backdoor using C# with 3-second polling and TripleDES-encrypted credentials targeting Indian government; SheetAgent/Operation ShadowRecruit (Seqrite, July 2026) — a .NET RAT leveraging ControlR RMM and Google Sheets, also attributed to APT36; and GRIDTIDE (Google/Mandiant, February 2026) — a C-based backdoor from China-nexus UNC2814 targeting telecoms across 42 countries with AES-128-CBC encrypted Sheets C2 and SoftEther VPN infrastructure. The Myanmar-targeting aspect also parallels Operation QUICSILVER (Seqrite, August 2026), a China-nexus espionage campaign using Cloudflare Workers dead-drop resolvers with QUIC/HTTP-3 transport against Myanmar government IT personnel.
Detection Guidance
The report provides a YARA rule (MALWAREINFO_Fake_GlobalProtect_Myanmar_Sheets_C2) matching the gate paths (X-Bot-Secret, /config0), Sheets protocol markers (val-, command-, out-), and campaign-specific strings (SheetsBot/1.0, AmountOfFreeDiskSpace, GlobalProtectVPNUpdate). The report warns against globally blocking workers.dev, oauth2.googleapis.com, or sheets.googleapis.com, recommending instead to correlate the specific rare hostname/URI path with the unsigned executable, custom user-agent, geolocation request, install path, and process ancestry.
MITRE ATT&CK techniques used in TL-2026-2368
Defense Evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1480 Execution Guardrails; T1574 Hijack Execution Flow
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter
Initial Access
Affected products and versions in Fake GlobalProtect MSI Targets Myanmar Using Cloudflare
- Palo Alto Networks — GlobalProtect
Vulnerable versions: Brand impersonated — no actual vulnerability in GlobalProtect
Remediation for Fake GlobalProtect MSI Targets Myanmar Using Cloudflare
Immediate actions
- Block Cloudflare Workers domain sheets-config-gate.hewlett-pack{1..9}.workers.dev at proxy/DNS level
- Block execution of unsigned GlobalProtect.msi via application control policies (AppLocker/WDAC)
- Search for GlobalProtectVPN RunOnce keys (HKCU+HKLM) and GlobalProtectVPNUpdate scheduled task
- Inspect C:\Program Files\PaloAlto\GlobalProtect VPN\ for trojanized WININET.dll and unsigned binaries
Workarounds
- Restrict msiexec execution to signed/approved installer packages via AppLocker
- Block unauthorized Cloudflare Workers subdomains via DNS filtering at proxy layer
- Monitor ip-api.com DNS queries from endpoints as geolocation-gating indicator
- Enable logging of msiexec /Install command-line arguments for incident response visibility
Longer-term hardening
- Deploy EDR rules monitoring msiexec.exe spawning unsigned child processes into non-standard paths
- Monitor for Google Sheets API traffic from non-browser processes on corporate endpoints
- Implement network detection for SheetsBot/1.0 user-agent from non-browser processes
- Deploy YARA rule MALWAREINFO_Fake_GlobalProtect_Myanmar_Sheets_C2 for historical and live hunting
Timeline of Fake GlobalProtect MSI Targets Myanmar Using Cloudflare
- MSI last saved timestamp (2026-08-19 06:09:17 UTC, 18 seconds after EXE build — consistent with packaging)
- GlobalProtect.exe PE header timestamp (attacker-controlled; indicates build date 2026-08-19 06:08:59 UTC)
- Malpedia catalogs sample under family designation win.unidentified_126; archive.org snapshot taken 2026-09-04
- Malware INFO Research Team publishes full analysis report with YARA rule, detailed reverse engineering, IOCs, and detection guidance
- OAuth JWT constructed with RS256 signature; successful token exchange at oauth2.googleapis.com; Google Sheets C2 handshake observed (A1 cell read, B1 cell write with victim IP, C1 cell poll)
- Cloudflare Workers config gate contacted at sheets-config-gate.hewlett-pack1.workers.dev/config0; X-Bot-Secret header sent; Google Cloud credentials (project elliptical-tree-505904-p7, client ID, private key) recovered from gate response
- Dynamic analysis session: malware executes and geolocation check to ip-api.com confirms Myanmar (countryCode: MM); process exits after ~2.86s
Sources cited for Fake GlobalProtect MSI Targets Myanmar Using Cloudflare
- Fake GlobalProtect MSI Targets Myanmar Using Cloudflare and Google Sheets as C2
- Malpedia: win.unidentified_126
- Archive.org mirror of Malware INFO analysis
- The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers Voldemort
- APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP
- Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers
- Disrupting GRIDTIDE: Global Espionage Campaign Using Google Sheets
- HoneyMyte Upgrades CoolClient with Signed Windows Kernel Rootkit
- Operation QUICSILVER: China-Nexus Actor Targets Myanmar Using QUICAgent and Cloudflare Workers
- Unit 42: Fake GlobalProtect Delivers WikiLoader via SEO Poisoning
Detection coverage for TL-2026-2368
As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2368 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.