🌐 Nation-State Threats

GRIDTIDE Busted: China's Cloud-Sneaking Spies Cut Off

Google slammed the door on UNC2814's GRIDTIDE campaign. China's spies hid in plain sight—using legit cloud tools. Pathetic, yet brilliant.

GRIDTIDE infection lifecycle diagram showing backdoor persistence and C2 via Google Sheets

⚡ Key Takeaways

  • Google and Mandiant disrupted UNC2814's GRIDTIDE, hitting 53 victims in 42 countries. 𝕏
  • Attackers abused Google Sheets API for stealthy C2—no vulnerabilities exploited. 𝕏
  • Expect copycats; cloud abuse is the new state-spy normal. 𝕏
Published by

theAIcatchup

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by Mandiant Blog

Stay in the loop

The week's most important stories from theAIcatchup, delivered once a week.