Hackers Using Google Cloud Storage to Bypass Email Filters and Deliver Remcos RAT
ID: bff3b600-4fe9-5219-bcc5-21f1c1e9004b
STIX ID: report--bff3b600-4fe9-5219-bcc5-21f1c1e9004b
Feed Name: cybersecurityNews.com
A phishing campaign leverages trusted Google Cloud Storage links to host fake Google Drive login pages that harvest credentials and deliver a JavaScript downloader which executes a multi-stage infection (VBS, PowerShell, fileless .NET loader) ultimately deploying the Remcos RAT; the chain uses time-based sandbox evasion, living-off-the-land binaries (RegSvcs.exe) for process hollowing, and establishes persistence to enable credential theft, surveillance, and potential lateral movement or ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
