Threat reportMalwareTL-2026-2368

Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2

highACTIVE

Fake GlobalProtect MSI Targets Myanmar Using Cloudflare (TL-2026-2368), also tracked as win.unidentified_126, is a high-severity malware campaign, first published 2026-09-07. It has no confirmed attribution, affects Palo Alto Networks GlobalProtect, maps to 9 MITRE ATT&CK techniques (T1036, T1053, T1059), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-2368

Threat ID
TL-2026-2368
Also known as
win.unidentified_126
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration
Target regions
myanmar, Southeast Asia
Detection rules
9
Indicators of compromise
22

Malware and tooling in Fake GlobalProtect MSI Targets Myanmar Using Cloudflare

Malware and tooling: cmd - S0106

How Fake GlobalProtect MSI Targets Myanmar Using Cloudflare works

An unsigned MSI masquerading as Palo Alto Networks GlobalProtect VPN delivers a staged backdoor targeting Myanmar. The malware uses a geolocation check (ip-api.com) to restrict execution to Myanmar, then establishes a Cloudflare Workers config gate for credential retrieval followed by Google Sheets API for command-and-control. The sample could not be attributed to any known threat actor and is cataloged under Malpedia family win.unidentified_126.

On 2026-09-02, the Malware INFO Research Team published an analysis of a malicious MSI installer masquerading as Palo Alto Networks GlobalProtect VPN (version 11.5.0, manufacturer 'PaloAlto') targeting users in Myanmar. The delivery chain begins with a spearphishing email containing a link to a Google Sites landing page, which serves the malicious MSI.

Delivery and Initial Execution

The MSI (GlobalProtect.msi, 3,475,968 bytes, SHA-256 a124caa58d956c7430ecb8772a3794266235917670c5b56564342bd1456897e7) is unsigned and forges its metadata to impersonate a legitimate Palo Alto Networks installer. It installs to C:\Program Files\PaloAlto\GlobalProtect VPN\ with ALLUSERS=2 (per-machine). The installer action GlobalProtect.exe /Install launches the embedded payload executable (GlobalProtect.exe, 425,984 bytes, SHA-256 33d696728101c9caf6ebb215ba176bbb94e5cc16218b574029b622fd6e3bee8c, PE32+ x64 Windows GUI, unsigned). The MSI drops and locally loads bcrypt.dll (valid Microsoft-signed), CRYPT32.dll (valid Microsoft-signed), and a trojanized WININET.dll (5,039,616 bytes, unsigned) into the app directory, exhibiting DLL binary-planting behavior.

Configuration Decryption

The embedded GlobalProtect.exe decrypts its configuration blobs using AES-256-CBC with a key derived from SHA-256('AmountOfFreeDiskSpace'), a form of environmental keying. The IV is the first 16 bytes of each blob. Decryption recovers: the geolocation host (ip-api.com), the installation directory, the Cloudflare Workers gate URL, the gate header name (X-Bot-Secret), and the Windows command-shell prefix.

Geolocation Execution Guardrail

Upon execution, the malware sends a GET /json request to ip-api.com (port 80) with the custom user-agent 'SheetsBot/1.0'. The response containing country: Myanmar, countryCode: MM is verified before proceeding. This geolocation gate restricts execution to Myanmar-based victims. The full process lifetime for this check was approximately 2.86 seconds, after which the process exited with status 0.

Cloudflare Workers Config Gate

After passing the geolocation check, the malware contacts a Cloudflare Workers endpoint at https://sheets-config-gate.hewlett-pack{1..9}.workers.dev/config0, sending the X-Bot-Secret header. Only hewlett-pack1 was observed in DNS; hosts 2-9 existed only in writable private memory. The config gate response (observed via InternetReadFile in the debugger) returns: google_creds, spreadsheet_id, project_id, private_key_id, private_key, client_email, and client_id. BeaconBeagle query returned no match for the workers.dev domain.

Google Cloud OAuth and Sheets API C2

Using the recovered credentials (project elliptical-tree-505904-p7, client ID 101714939433347726433), the malware constructs a JWT with RS256 signature, claims aud=https://oauth2.googleapis.com/token, scope=https://www.googleapis.com/auth/spreadsheets, and a 3,600-second expiry. A successful OAuth token exchange is observed, followed by Google Sheets API operations. The C2 protocol uses four fixed columns: Sheet1!A for victim device identification (val- marker, scanned rows 1-100), Sheet1!B for public IP/victim metadata, Sheet1!C for operator command queue (command- marker, polled but no command observed), and Sheet1!D for command output (out- marker, not observed). Commands are designed to execute via a hidden cmd.exe child process (CREATE_NO_WINDOW) with inherited stdout/stderr pipes.

Persistence

The malware establishes persistence through two mechanisms: GlobalProtectVPN RunOnce values under both HKCU and HKLM registry hives, and a scheduled task named GlobalProtectVPNUpdate with PaloAlto-themed metadata referencing GlobalProtect.exe.

Attribution

The Malware INFO Research Team explicitly states: 'We found no evidence sufficient to identify this sample as CoolClient, connect it to HoneyMyte, or attribute it to another named actor.' The Malpedia entry catalogs the sample under the temporary family designation win.unidentified_126. The Kaspersky HoneyMyte/CoolClient report (August 2026) is noted as regional context only — that chain used PlugX, DLL sideloading via a legitimate Sangfor application, synchost.exe injection, and a kernel rootkit, none of which overlap with this sample.

Related Sheets-C2 Ecosystem

This campaign joins a growing ecosystem of malware families abusing Google Sheets as a C2 channel, each with distinct operational patterns: Voldemort (Proofpoint, August 2024) — a China-aligned TA415/APT41 campaign using individual spreadsheet tabs per victim with file exchange commands; SHEETCREEP (Zscaler, January 2026) — a Pakistan-linked APT36 backdoor using C# with 3-second polling and TripleDES-encrypted credentials targeting Indian government; SheetAgent/Operation ShadowRecruit (Seqrite, July 2026) — a .NET RAT leveraging ControlR RMM and Google Sheets, also attributed to APT36; and GRIDTIDE (Google/Mandiant, February 2026) — a C-based backdoor from China-nexus UNC2814 targeting telecoms across 42 countries with AES-128-CBC encrypted Sheets C2 and SoftEther VPN infrastructure. The Myanmar-targeting aspect also parallels Operation QUICSILVER (Seqrite, August 2026), a China-nexus espionage campaign using Cloudflare Workers dead-drop resolvers with QUIC/HTTP-3 transport against Myanmar government IT personnel.

Detection Guidance

The report provides a YARA rule (MALWAREINFO_Fake_GlobalProtect_Myanmar_Sheets_C2) matching the gate paths (X-Bot-Secret, /config0), Sheets protocol markers (val-, command-, out-), and campaign-specific strings (SheetsBot/1.0, AmountOfFreeDiskSpace, GlobalProtectVPNUpdate). The report warns against globally blocking workers.dev, oauth2.googleapis.com, or sheets.googleapis.com, recommending instead to correlate the specific rare hostname/URI path with the unsigned executable, custom user-agent, geolocation request, install path, and process ancestry.

MITRE ATT&CK techniques used in TL-2026-2368

Defense Evasion

T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1480 Execution Guardrails; T1574 Hijack Execution Flow

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1566 Phishing

Affected products and versions in Fake GlobalProtect MSI Targets Myanmar Using Cloudflare

  • Palo Alto Networks — GlobalProtect
    Vulnerable versions: Brand impersonated — no actual vulnerability in GlobalProtect

Remediation for Fake GlobalProtect MSI Targets Myanmar Using Cloudflare

Immediate actions

  • Block Cloudflare Workers domain sheets-config-gate.hewlett-pack{1..9}.workers.dev at proxy/DNS level
  • Block execution of unsigned GlobalProtect.msi via application control policies (AppLocker/WDAC)
  • Search for GlobalProtectVPN RunOnce keys (HKCU+HKLM) and GlobalProtectVPNUpdate scheduled task
  • Inspect C:\Program Files\PaloAlto\GlobalProtect VPN\ for trojanized WININET.dll and unsigned binaries

Workarounds

  • Restrict msiexec execution to signed/approved installer packages via AppLocker
  • Block unauthorized Cloudflare Workers subdomains via DNS filtering at proxy layer
  • Monitor ip-api.com DNS queries from endpoints as geolocation-gating indicator
  • Enable logging of msiexec /Install command-line arguments for incident response visibility

Longer-term hardening

  • Deploy EDR rules monitoring msiexec.exe spawning unsigned child processes into non-standard paths
  • Monitor for Google Sheets API traffic from non-browser processes on corporate endpoints
  • Implement network detection for SheetsBot/1.0 user-agent from non-browser processes
  • Deploy YARA rule MALWAREINFO_Fake_GlobalProtect_Myanmar_Sheets_C2 for historical and live hunting

Timeline of Fake GlobalProtect MSI Targets Myanmar Using Cloudflare

  • MSI last saved timestamp (2026-08-19 06:09:17 UTC, 18 seconds after EXE build — consistent with packaging)
  • GlobalProtect.exe PE header timestamp (attacker-controlled; indicates build date 2026-08-19 06:08:59 UTC)
  • Malpedia catalogs sample under family designation win.unidentified_126; archive.org snapshot taken 2026-09-04
  • Malware INFO Research Team publishes full analysis report with YARA rule, detailed reverse engineering, IOCs, and detection guidance
  • OAuth JWT constructed with RS256 signature; successful token exchange at oauth2.googleapis.com; Google Sheets C2 handshake observed (A1 cell read, B1 cell write with victim IP, C1 cell poll)
  • Cloudflare Workers config gate contacted at sheets-config-gate.hewlett-pack1.workers.dev/config0; X-Bot-Secret header sent; Google Cloud credentials (project elliptical-tree-505904-p7, client ID, private key) recovered from gate response
  • Dynamic analysis session: malware executes and geolocation check to ip-api.com confirms Myanmar (countryCode: MM); process exits after ~2.86s

Sources cited for Fake GlobalProtect MSI Targets Myanmar Using Cloudflare

Detection coverage for TL-2026-2368

As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2368 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats