Analysis Finds .NET RAT Using Google Sheets C2 in UAE–India-Themed ISO

Summary
A researcher analyzed an ISO containing a .NET dropper and a previously unseen RAT dubbed PulseRAT. The RAT uses Google Sheets for command and control, collects system information, and executes attacker-supplied PowerShell commands.
Key points
- The ISO, named for a UAE–India strategic partnership event, contains a Windows shortcut that launches a .NET dropper.
- The dropper installs the RAT as vaultsvc.exe under the user's Local AppData Microsoft\Vault directory and creates a scheduled task that runs after three minutes and at user logon.
- The researcher provisionally names the .NET payload PulseRAT; its embedded service account and spreadsheet ID are used to access Google Sheets for command and control.
- PulseRAT creates a spreadsheet tab for each victim, records timestamps and system information, and checks the sheet for commands.
- The malware decodes base64 PowerShell commands, runs them in an in-process PowerShell runspace, and writes encoded output back to the spreadsheet.
- The researcher could not access the spreadsheet and says the associated service account may have been deleted.
- A separate Excel file shared a machine name with the shortcut metadata, but the researcher describes the connection as weak and found no specific threat associated with that file.
Article Details
- Attack Vectors
- The ISO contains an LNK file that runs an accompanying .NET dropper.
- The dropper installs PulseRAT as %LOCALAPPDATA%\Microsoft\Vault\vaultsvc.exe and creates a scheduled task for its initial execution and persistence.
- PulseRAT uses an attacker-controlled Google Spreadsheet to receive base64-encoded PowerShell commands and return encoded command output.
- Defensive Notes
- The scheduled task is named WindowsVaultSyncService and runs vaultsvc.exe three minutes after creation and when the current user logs on.
- PulseRAT executes commands in a PowerShell runspace without spawning a PowerShell process.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
sheet5@sheet5-495707[.]iam[.]gserviceaccount[.]com | Service account embedded in PulseRAT for authentication to its attacker-controlled Google Spreadsheet. | |
| SHA256 | 1ba67bb1cfad42446880cca53cbd05fe66d7514b2bb139b48e5c63adff14be7b | Hash of the ISO containing the malicious LNK and dropper. |
| SHA256 | 2cc7c2d8653c98e5bac32fcaf5e45b861efb4bb87df3b3f96285edb475e75bba | Hash of the .NET dropper. |
| SHA256 | 3b16f1a2d74578beed77d870350d75202b54bd5b0460c8cf79316bc9ba812907 | Hash of the LNK that runs the dropper. |
| SHA256 | 62d62950ff7a0e43550a5d0ba55d32d5083b9de5538e0f012e406b6d951e16aa | Hash of the PulseRAT payload saved as vaultsvc.exe. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationPulseRAT base64-decodes and XOR-decrypts embedded strings for its Spreadsheet ID and service account.T1053.005 · Scheduled TaskThe dropper creates the WindowsVaultSyncService scheduled task to execute vaultsvc.exe after three minutes and at user logon.T1059.001 · PowerShellPulseRAT runs systeminfo and attacker-supplied commands through an in-process PowerShell runspace.T1070.004 · File DeletionAfter creating the scheduled task, the dropper self-deletes.T1082 · System Information DiscoveryPulseRAT runs systeminfo once and writes its output to the victim's sheet.T1102.002 · Bidirectional CommunicationPulseRAT reads commands from an attacker-controlled Google Spreadsheet and writes command output and heartbeat data back to it.