logo

Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes

ID: 918ffa20-50b3-53c8-a9cf-3aba46065488

STIX ID: report--918ffa20-50b3-53c8-a9cf-3aba46065488

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Abinaya

...
...

eSentire observed a fast-moving campaign where attackers used email bombing and Microsoft Teams voice-phishing to socially engineer a user into granting remote control via Windows Quick Assist, then deployed a Java-based Nimbus RAT from a compromised Microsoft 365 tenant. Nimbus RAT uses legitimate cloud services (SharePoint for delivery and Google Drive/Sheets as C2) and includes credential-harvesting and modular remote-access capabilities, enabling stealthy, cross-tenant campaigns that are difficult to detect via traditional domain- or signature-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.