s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.gridtide

📛 Threat Title

Malware family: GRIDTIDE

Category: GRIDTIDE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.gridtide`. Printable name: GRIDTIDE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.gridtide VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gridtide

IOC database

Type
domain
Value
elf.gridtide
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.gridtide

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gridtide

References (1)

Remediations (10)

  • web:cloud.google.com

    The group's recent activity leveraging GRIDTIDE malware has primarily focused on targeting telecommunications providers on a worldwide scale, but UNC2814 also targeted government organizations during this campaign. GTIG confirmed 53 intrusions by UNC2814 in 42 total nations globally, and identified suspected targeting in at least 20 other nations.

  • web:gurucul.com

    The GRIDTIDE global cyber espionage campaign shows how attackers abuse cloud APIs and trusted tools for long-term surveillance and data access.

  • web:hackmag.com

    The researchers write that the group's key tool was the GRIDTIDE backdoor, written in C. Its main feature is the use of the Google Sheets API as a command-and-control channel. The malware authenticated via a Google Service Account using a hard-coded private key, and then turned a regular spreadsheet into a full-fledged C2.

  • web:liora.io

    The GRIDTIDE backdoor represented a sophisticated evolution in cyber espionage techniques. The malware communicated with its operators by polling specific cells within Google Sheets, making malicious traffic appear as legitimate cloud service usage.

  • web:securityarsenal.com

    Google and industry partners disrupted the prolific China-nexus UNC2814 group. Learn how the GRIDTIDE campaign infiltrated 53 orgs and how to hunt for these threats.

  • web:stateofsurveillance.org

    Home News Google Disrupts UNC2814 TL;DR: Google disclosed on February 25 that it worked with Mandiant to dismantle infrastructure used by UNC2814, a suspected Chinese government-linked hacking group that breached 53 organizations across 42 countries. The attackers used a custom backdoor called GRIDTIDE that hid its command-and-control traffic inside Google Sheets — making hostile ...

  • web:thearabianpost.com

    The implications extend beyond one malware family . In one investigated case, Google said the attackers planted GRIDTIDE on an endpoint holding personally identifiable information including names, phone numbers, dates of birth, place of birth, voter ID numbers and national ID numbers.

  • web:thehackernews.com

    Google disrupts China-linked UNC2814 after 53 breaches in 42 countries using GRIDTIDE via Google Sheets API.

  • web:www.bleepingcomputer.com

    The first cell in the spreadsheet, A1, is the command/status cell, which GRIDTIDE polls constantly to receive instructions. If any exist, the malware overwrites them with a status string.

  • web:www.rescana.com

    The UNC2814 campaign represents a highly sophisticated, multi-year cyber espionage operation targeting telecommunications and government sectors worldwide. The group's hallmark was the deployment of the GRIDTIDE backdoor, a C-based malware that exploited the Google Sheets API for C2 communications. This approach allowed attackers to disguise malicious traffic as ordinary SaaS activity ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.