# Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2

> An unsigned MSI masquerading as Palo Alto Networks GlobalProtect VPN delivers a staged backdoor targeting Myanmar. The malware uses a geolocation check (ip-api.com) to restrict execution to Myanmar, then establishes a Cloudflare Workers config gate for credential retrieval followed by Google Sheets API for command-and-control. The sample could not be attributed to any known threat actor and is cataloged under Malpedia family win.unidentified_126.

- **Published:** 2026-09-07T00:00:00Z
- **Last reviewed:** 2026-09-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2368
- **ID:** TL-2026-2368
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-09-02, the Malware INFO Research Team published an analysis of a malicious MSI installer masquerading as Palo Alto Networks GlobalProtect VPN (version 11.5.0, manufacturer 'PaloAlto') targeting users in Myanmar. The delivery chain begins with a spearphishing email containing a link to a Google Sites landing page, which serves the malicious MSI.

Delivery and Initial Execution

The MSI (GlobalProtect.msi, 3,475,968 bytes, SHA-256 a124caa58d956c7430ecb8772a3794266235917670c5b56564342bd1456897e7) is unsigned and forges its metadata to impersonate a legitimate Palo Alto Networks installer. It installs to C:\Program Files\PaloAlto\GlobalProtect VPN\ with ALLUSERS=2 (per-machine). The installer action GlobalProtect.exe /Install launches the embedded payload executable (GlobalProtect.exe, 425,984 bytes, SHA-256 33d696728101c9caf6ebb215ba176bbb94e5cc16218b574029b622fd6e3bee8c, PE32+ x64 Windows GUI, unsigned). The MSI drops and locally loads bcrypt.dll (valid Microsoft-signed), CRYPT32.dll (valid Microsoft-signed), and a trojanized WININET.dll (5,039,616 bytes, unsigned) into the app directory, exhibiting DLL binary-planting behavior.

Configuration Decryption

The embedded GlobalProtect.exe decrypts its configuration blobs using AES-256-CBC with a key derived from SHA-256('AmountOfFreeDiskSpace'), a form of environmental keying. The IV is the first 16 bytes of each blob. Decryption recovers: the geolocation host (ip-api.com), the installation directory, the Cloudflare Workers gate URL, the gate header name (X-Bot-Secret), and the Windows command-shell prefix.

Geolocation Execution Guardrail

Upon execution, the malware sends a GET /json request to ip-api.com (port 80) with the custom user-agent 'SheetsBot/1.0'. The response containing country: Myanmar, countryCode: MM is verified before proceeding. This geolocation gate restricts execution to Myanmar-based victims. The full process lifetime for this check was approximately 2.86 seconds, after which the process exited with status 0.

Cloudflare Workers Config Gate

After passing the geolocation check, the malware contacts a Cloudflare Workers endpoint at https://sheets-config-gate.hewlett-pack{1..9}.workers.dev/config0, sending the X-Bot-Secret header. Only hewlett-pack1 was observed in DNS; hosts 2-9 existed only in writable private memory. The config gate response (observed via InternetReadFile in the debugger) returns: google_creds, spreadsheet_id, project_id, private_key_id, private_key, client_email, and client_id. BeaconBeagle query returned no match for the workers.dev domain.

Google Cloud OAuth and Sheets API C2

Using the recovered credentials (project elliptical-tree-505904-p7, client ID 101714939433347726433), the malware constructs a JWT with RS256 signature, claims aud=https://oauth2.googleapis.com/token, scope=https://www.googleapis.com/auth/spreadsheets, and a 3,600-second expiry. A successful OAuth token exchange is observed, followed by Google Sheets API operations. The C2 protocol uses four fixed columns: Sheet1!A for victim device identification (val- marker, scanned rows 1-100), Sheet1!B for public IP/victim metadata, Sheet1!C for operator command queue (command- marker, polled but no command observed), and Sheet1!D for command output (out- marker, not observed). Commands are designed to execute via a hidden cmd.exe child process (CREATE_NO_WINDOW) with inherited stdout/stderr pipes.

Persistence

The malware establishes persistence through two mechanisms: GlobalProtectVPN RunOnce values under both HKCU and HKLM registry hives, and a scheduled task named GlobalProtectVPNUpdate with PaloAlto-themed metadata referencing GlobalProtect.exe.

Attribution

The Malware INFO Research Team explicitly states: 'We found no evidence sufficient to identify this sample as CoolClient, connect it to HoneyMyte, or attribute it to another named actor.' The Malpedia entry catalogs the sample under the temporary family designation win.unidentified_126. The Kaspersky HoneyMyte/CoolClient report (August 2026) is noted as regional context only — that chain used PlugX, DLL sideloading via a legitimate Sangfor application, synchost.exe injection, and a kernel rootkit, none of which overlap with this sample.

Related Sheets-C2 Ecosystem

This campaign joins a growing ecosystem of malware families abusing Google Sheets as a C2 channel, each with distinct operational patterns: Voldemort (Proofpoint, August 2024) — a China-aligned TA415/APT41 campaign using individual spreadsheet tabs per victim with file exchange commands; SHEETCREEP (Zscaler, January 2026) — a Pakistan-linked APT36 backdoor using C# with 3-second polling and TripleDES-encrypted credentials targeting Indian government; SheetAgent/Operation ShadowRecruit (Seqrite, July 2026) — a .NET RAT leveraging ControlR RMM and Google Sheets, also attributed to APT36; and GRIDTIDE (Google/Mandiant, February 2026) — a C-based backdoor from China-nexus UNC2814 targeting telecoms across 42 countries with AES-128-CBC encrypted Sheets C2 and SoftEther VPN infrastructure. The Myanmar-targeting aspect also parallels Operation QUICSILVER (Seqrite, August 2026), a China-nexus espionage campaign using Cloudflare Workers dead-drop resolvers with QUIC/HTTP-3 transport against Myanmar government IT personnel.

Detection Guidance

The report provides a YARA rule (MALWAREINFO_Fake_GlobalProtect_Myanmar_Sheets_C2) matching the gate paths (X-Bot-Secret, /config0), Sheets protocol markers (val-, command-, out-), and campaign-specific strings (SheetsBot/1.0, AmountOfFreeDiskSpace, GlobalProtectVPNUpdate). The report warns against globally blocking workers.dev, oauth2.googleapis.com, or sheets.googleapis.com, recommending instead to correlate the specific rare hostname/URI path with the unsigned executable, custom user-agent, geolocation request, install path, and process ancestry.

## MITRE ATT&CK

- T1566 Phishing
- T1036 Masquerading
- T1218 System Binary Proxy Execution
- T1574 Hijack Execution Flow
- T1140 Deobfuscate/Decode Files or Information
- T1480 Execution Guardrails
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job

## Sources

- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare and Google Sheets as C2](https://www.malwareinfo.app/blog/posts/fake-globalprotect-msi-targets-myanmar-cloudflare-google-sheets-c2/)
- [Malpedia: win.unidentified_126](https://malpedia.caad.fkie.fraunhofer.de/library/978fd82c-eb7e-4ad4-99ed-8a291c58dd9d/)
- [Archive.org mirror of Malware INFO analysis](https://web.archive.org/20260904110121/https://www.malwareinfo.app/blog/posts/fake-globalprotect-msi-targets-myanmar-cloudflare-google-sheets-c2/)
- [The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers Voldemort](https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort)
- [APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP](https://www.zscaler.com/blogs/security-research/apt-attacks-target-indian-government-using-sheetcreep-firepower-and)
- [Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers](https://www.seqrite.com/blog/operation-shadowrecruit-a-recruitment-themed-malware-campaign-leveraging-controlr-and-google-sheets-to-target-indian-job-seekers/)
- [Disrupting GRIDTIDE: Global Espionage Campaign Using Google Sheets](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaign)
- [HoneyMyte Upgrades CoolClient with Signed Windows Kernel Rootkit](https://securelist.com/honeymyte-coolclient-kernel-rootkit/)
- [Operation QUICSILVER: China-Nexus Actor Targets Myanmar Using QUICAgent and Cloudflare Workers](https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar/)
- [Unit 42: Fake GlobalProtect Delivers WikiLoader via SEO Poisoning](https://unit42.paloaltonetworks.com/wikiloader-fake-globalprotect/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2368
