TF-MAL-elf.gridtide
📛 Threat Title
Malware family: GRIDTIDE
Description
ThreatFox malware family `elf.gridtide`. Printable name: GRIDTIDE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.gridtide
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gridtide
IOC database
- Type
- domain
- Value
elf.gridtide- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.gridtide
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gridtide
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cloud.google.com
The group's recent activity leveraging GRIDTIDE malware has primarily focused on targeting telecommunications providers on a worldwide scale, but UNC2814 also targeted government organizations during this campaign. GTIG confirmed 53 intrusions by UNC2814 in 42 total nations globally, and identified suspected targeting in at least 20 other nations.
-
web:gurucul.com
The GRIDTIDE global cyber espionage campaign shows how attackers abuse cloud APIs and trusted tools for long-term surveillance and data access.
-
web:hackmag.com
The researchers write that the group's key tool was the GRIDTIDE backdoor, written in C. Its main feature is the use of the Google Sheets API as a command-and-control channel. The malware authenticated via a Google Service Account using a hard-coded private key, and then turned a regular spreadsheet into a full-fledged C2.
-
web:liora.io
The GRIDTIDE backdoor represented a sophisticated evolution in cyber espionage techniques. The malware communicated with its operators by polling specific cells within Google Sheets, making malicious traffic appear as legitimate cloud service usage.
-
web:securityarsenal.com
Google and industry partners disrupted the prolific China-nexus UNC2814 group. Learn how the GRIDTIDE campaign infiltrated 53 orgs and how to hunt for these threats.
-
web:stateofsurveillance.org
Home News Google Disrupts UNC2814 TL;DR: Google disclosed on February 25 that it worked with Mandiant to dismantle infrastructure used by UNC2814, a suspected Chinese government-linked hacking group that breached 53 organizations across 42 countries. The attackers used a custom backdoor called GRIDTIDE that hid its command-and-control traffic inside Google Sheets — making hostile ...
-
web:thearabianpost.com
The implications extend beyond one malware family . In one investigated case, Google said the attackers planted GRIDTIDE on an endpoint holding personally identifiable information including names, phone numbers, dates of birth, place of birth, voter ID numbers and national ID numbers.
-
web:thehackernews.com
Google disrupts China-linked UNC2814 after 53 breaches in 42 countries using GRIDTIDE via Google Sheets API.
-
web:www.bleepingcomputer.com
The first cell in the spreadsheet, A1, is the command/status cell, which GRIDTIDE polls constantly to receive instructions. If any exist, the malware overwrites them with a status string.
-
web:www.rescana.com
The UNC2814 campaign represents a highly sophisticated, multi-year cyber espionage operation targeting telecommunications and government sectors worldwide. The group's hallmark was the deployment of the GRIDTIDE backdoor, a C-based malware that exploited the Google Sheets API for C2 communications. This approach allowed attackers to disguise malicious traffic as ordinary SaaS activity ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.