Security researchers have identified SHEETCREEP, a C# remote access trojan that leverages Google Sheets API as a command-and-control infrastructure to target diplomatic organizations. The malware’s use of Google’s legitimate API infrastructure allows it to evade traditional network detection methods while maintaining communication with attackers. The discovery highlights an emerging threat technique where adversaries abuse trusted cloud services for malicious purposes.