Analysis Finds .NET RAT Using Google Sheets C2 in UAE–India-Themed ISO

· Original article ↗

Summary

A researcher analyzed an ISO containing a .NET dropper and a previously unseen RAT dubbed PulseRAT. The RAT uses Google Sheets for command and control, collects system information, and executes attacker-supplied PowerShell commands.

Key points

  • The ISO, named for a UAE–India strategic partnership event, contains a Windows shortcut that launches a .NET dropper.
  • The dropper installs the RAT as vaultsvc.exe under the user's Local AppData Microsoft\Vault directory and creates a scheduled task that runs after three minutes and at user logon.
  • The researcher provisionally names the .NET payload PulseRAT; its embedded service account and spreadsheet ID are used to access Google Sheets for command and control.
  • PulseRAT creates a spreadsheet tab for each victim, records timestamps and system information, and checks the sheet for commands.
  • The malware decodes base64 PowerShell commands, runs them in an in-process PowerShell runspace, and writes encoded output back to the spreadsheet.
  • The researcher could not access the spreadsheet and says the associated service account may have been deleted.
  • A separate Excel file shared a machine name with the shortcut metadata, but the researcher describes the connection as weak and found no specific threat associated with that file.

Article Details

Attack Vectors
  • The ISO contains an LNK file that runs an accompanying .NET dropper.
  • The dropper installs PulseRAT as %LOCALAPPDATA%\Microsoft\Vault\vaultsvc.exe and creates a scheduled task for its initial execution and persistence.
  • PulseRAT uses an attacker-controlled Google Spreadsheet to receive base64-encoded PowerShell commands and return encoded command output.
Defensive Notes
  • The scheduled task is named WindowsVaultSyncService and runs vaultsvc.exe three minutes after creation and when the current user logs on.
  • PulseRAT executes commands in a PowerShell runspace without spawning a PowerShell process.

Indicators of compromise

TypeIndicatorContext
EMAILsheet5@sheet5-495707[.]iam[.]gserviceaccount[.]comService account embedded in PulseRAT for authentication to its attacker-controlled Google Spreadsheet.
SHA2561ba67bb1cfad42446880cca53cbd05fe66d7514b2bb139b48e5c63adff14be7bHash of the ISO containing the malicious LNK and dropper.
SHA2562cc7c2d8653c98e5bac32fcaf5e45b861efb4bb87df3b3f96285edb475e75bbaHash of the .NET dropper.
SHA2563b16f1a2d74578beed77d870350d75202b54bd5b0460c8cf79316bc9ba812907Hash of the LNK that runs the dropper.
SHA25662d62950ff7a0e43550a5d0ba55d32d5083b9de5538e0f012e406b6d951e16aaHash of the PulseRAT payload saved as vaultsvc.exe.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles