Home Cyber Security

New ‘GRIDTIDE’ Malware Abuses Google Sheets for Covert Command-and-Control

A newly uncovered backdoor dubbed “GRIDTIDE” has revealed a sophisticated evolution in cyber espionage tradecraft  turning legitimate cloud spreadsheets into covert command-and-control (C2) infrastructure.

The malware, identified during a Mandiant investigation and analysed by Google’s Threat Intelligence Group (GTIG), was deployed by suspected PRC-nexus threat actor UNC2814 in late 2025.

Written in C, GRIDTIDE connects to attacker-controlled Google Sheets to receive instructions and exfiltrate stolen data. By blending malicious communications into legitimate SaaS traffic, the malware effectively evades traditional detection methods.

Importantly, Google confirmed this activity was not the result of a vulnerability in Google Sheets. Instead, attackers abused normal functionality part of a broader trend in which threat actors leverage trusted SaaS platforms rather than build and maintain custom infrastructure.

GTIG warned that GRIDTIDE’s architecture is adaptable. While this campaign used Google Sheets, the same technique could easily be replicated using other cloud-based spreadsheet platforms.

Security experts anticipate further historic compromises may come to light as organisations begin hunting for indicators of compromise (IOCs) published alongside the research.

The discovery highlights a growing shift in espionage tactics: hiding malicious activity inside trusted cloud ecosystems.