Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html
ONE SENTENCE SUMMARY:
Google and partners disrupted UNC2814’s China-linked espionage campaign using Google Sheets C2 backdoor GRIDTIDE across governments and telecoms worldwide.
MAIN POINTS:
- Google, Mandiant, and partners dismantled suspected China-nexus UNC2814 infrastructure.
- Confirmed breaches impacted at least 53 organizations across 42 countries.
- Additional suspected infections span more than 20 other nations.
- Tracking since 2017 revealed SaaS API calls used as disguised command-and-control.
- GRIDTIDE backdoor abuses Google Sheets API to blend C2 within legitimate traffic.
- Malware supports file transfer and arbitrary shell command execution on compromised systems.
- Initial access likely involves exploiting web servers and edge systems, still under investigation.
- Lateral movement utilized service accounts and SSH within victim environments.
- LotL binaries enabled reconnaissance, privilege escalation, and persistence via systemd service xapt.
- SoftEther VPN Bridge established encrypted outbound connectivity, consistent with other Chinese groups’ tactics.
TAKEAWAYS:
- SaaS platforms can be repurposed as stealthy C2 channels via legitimate APIs.
- Edge appliances remain high-risk entry points due to exposure and weak detection coverage.
- Persistence commonly leverages native services (e.g., systemd) to survive reboots and scrutiny.
- Telecom and government sectors face sustained, global-scale espionage with high evasion capability.
- Large disruptions may be temporary; defenders should expect rapid attacker reconstitution efforts.