logo

New Phishing Attack Via Google Storage Deploys Remcos RAT

ID: 833dde72-2e5d-52f5-88f6-1dd6a8930e87

STIX ID: report--833dde72-2e5d-52f5-88f6-1dd6a8930e87

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A phishing campaign is abusing Google Cloud Storage (googleapis.com) to host pages that impersonate Google Drive and deliver the Remcos RAT through a multi-stage infection: JavaScript redirects or automatic downloads fetch obfuscated archives, a VBScript/PowerShell dropper retrieves the Remcos payload which is injected via process hollowing and establishes persistence (e.g., `HKEY_CURRENT_USER\Software\Remcos-{ID}`) and encrypted C2. Because the attack leverages trusted Google infrastructure, email and web filters may not flag the malicious links; recommended defenses include monitoring outbound googleapis.com usage outside normal workflows, enforcing script execution policies, enabling behavioral endpoint detection, and user training to avoid unexpected links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.