Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
    Cybersecurity

    Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries

    adminBy adminFebruary 25, 2026No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananFeb 25, 2026Cyber Espionage / Network Security

    Google on Wednesday disclosed that it worked with industry partners to disrupt the infrastructure of a suspected China-nexus cyber espionage group tracked as UNC2814 that breached at least 53 organizations across 42 countries.

    “This prolific, elusive actor has a long history of targeting international governments and global telecommunications organizations across Africa, Asia, and the Americas,” Google Threat Intelligence Group (GTIG) and Mandiant said in a report published today.

    UNC2814 is also suspected to be linked to additional infections in more than 20 other nations. The tech giant, which has been tracking the threat actor since 2017, has been observed using API calls to communicate with software-as-a-service (SaaS) apps as command-and-control (C2) infrastructure. The idea, it added, is to disguise their malicious traffic as benign.

    Central to the hacking group’s operations is a novel backdoor dubbed GRIDTIDE that abuses Google Sheets API as a communication channel to disguise C2 traffic and facilitate the transfer of raw data and shell commands. It’s a C-based malware that supports file upload/download and the execution of arbitrary shell commands.

    Exactly how UNC2814 obtains initial access remains a topic of investigation, but the group is said to have a history of exploiting and compromising web servers and edge systems.

    Attacks mounted by the threat actor have leveraged a service account to move laterally within the environment via SSH. Also put to use are living-off-the-land (LotL) binaries to conduct reconnaissance, escalate privileges, and set up persistence for the backdoor.

    “To achieve persistence, the threat actor created a service for the malware at /etc/systemd/system/xapt.service, and once enabled, a new instance of the malware was spawned from /usr/sbin/xapt,” Google explained.

    Another noteworthy aspect is the deployment of SoftEther VPN Bridge to establish an outbound encrypted connection to an external IP address. It’s worth mentioning here that the abuse of SoftEther VPN has been linked to multiple Chinese hacking groups.

    There is evidence indicating that GRIDTIDE is dropped on endpoints containing personally identifiable information (PII), an aspect that’s consistent with cyber espionage activity focused on monitoring persons of interest. Google, however, noted that it did not observe any data exfiltration taking place during the course of the campaign.

    GRIDTIDE execution lifecycle

    GRIDTIDE’s C2 mechanism involves a cell-based polling mechanism, where specific roles are assigned to certain spreadsheet cells to enable bidirectional communication –

    • A1, to poll for attacker commands and overwrite it with a status response (e.g., S-C-R or Server-Command-Success)
    • A2-An, to transfer data, such as command output and files
    • V1, to store system data from the victim endpoint

    As part of the action, Google said it terminated all Google Cloud Projects controlled by the attacker, disabled all known UNC2814 infrastructure, and cut off access to attacker-controlled accounts and Google Sheets API calls leveraged by the actor for command-and-control (C2) purposes.

    The tech giant described UNC2814 as one of the “most far-reaching, impactful campaigns” encountered in recent years, adding that it has issued formal victim notifications to each of the targets and that it is actively supporting organizations with verified compromises resulting from this threat.

    The latest discovery is one of many concurrent efforts by Chinese nation-state groups to embed themselves into networks for long-term access. The development also highlights that the network edge continues to take the brunt of internet-wide exploitation attempts, with threat actors frequently exploiting vulnerabilities and misconfigurations in such appliances as a common entry point into enterprise networks.

    These appliances have become attractive targets in recent years as they typically lack endpoint malware detection, yet provide direct network access or pivot points to internal services if compromised.

    “The global scope of UNC2814’s activity, evidenced by confirmed or suspected operations in over 70 countries, underscores the serious threat facing telecommunications and government sectors, and the capacity for these intrusions to evade detection by defenders, Google said.

    “Prolific intrusions of this scale are generally the result of years of focused effort and will not be easily re-established. We expect that UNC2814 will work hard to re-establish its global footprint.”

    Breaches Campaign Countries disrupts Google GRIDTIDE UNC2814
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThe 10 Best PPC Ad Networks
    Next Article OpenAI COO says ChatGPT ad rollout will be “iterative”
    admin
    • Website

    Related Posts

    Quantum-Resistant Data Diode Secures Data on Edge Devices

    March 3, 2026

    AI Agents: The Next Wave Identity Dark Matter

    March 3, 2026

    New Defender deployment tool streamlines Windows device onboarding with single executable

    March 3, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Meta introduces click and engage-through attribution updates

    March 3, 2026

    How to Prevent Your Smartwatch Band From Irritating Your Skin

    March 3, 2026

    Quantum-Resistant Data Diode Secures Data on Edge Devices

    March 3, 2026

    I ditched my gas generator for battery backup, and I’m never looking back

    March 3, 2026
    Categories
    • Blogging (32)
    • Cybersecurity (577)
    • Privacy & Online Earning (81)
    • SEO & Digital Marketing (361)
    • Tech Tools & Mobile / Apps (714)
    • WiFi / Internet & Networking (103)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Meta introduces click and engage-through attribution updates

    March 3, 2026

    How to Prevent Your Smartwatch Band From Irritating Your Skin

    March 3, 2026

    Quantum-Resistant Data Diode Secures Data on Edge Devices

    March 3, 2026
    Most Popular
    • Meta introduces click and engage-through attribution updates
    • How to Prevent Your Smartwatch Band From Irritating Your Skin
    • Quantum-Resistant Data Diode Secures Data on Edge Devices
    • I ditched my gas generator for battery backup, and I’m never looking back
    • AI Agents: The Next Wave Identity Dark Matter
    • 9 Best Rewards Checking Accounts of March 2026
    • 5x the Pages, 70x the Citations, 1615x the Traffic
    • I stopped using my Kindle after setting up this gorgeous self-hosted book server
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.