logo

Hackers Using Google Cloud Storage to Bypass Email Filters and Deliver Remcos RAT

ID: bff3b600-4fe9-5219-bcc5-21f1c1e9004b

STIX ID: report--bff3b600-4fe9-5219-bcc5-21f1c1e9004b

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A phishing campaign leverages trusted Google Cloud Storage links to host fake Google Drive login pages that harvest credentials and deliver a JavaScript downloader which executes a multi-stage infection (VBS, PowerShell, fileless .NET loader) ultimately deploying the Remcos RAT; the chain uses time-based sandbox evasion, living-off-the-land binaries (RegSvcs.exe) for process hollowing, and establishes persistence to enable credential theft, surveillance, and potential lateral movement or ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.