logo

NANOREMOTE Malware Leverages Google Drive API for Command-and-Control (C2) to Attack Windows Systems

ID: c3bb26c5-d210-5960-97e4-b7e985c43c7e

STIX ID: report--c3bb26c5-d210-5960-97e4-b7e985c43c7e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

NANOREMOTE is a sophisticated Windows backdoor that leverages Google Drive API as a covert C2 channel, authenticating via hard-coded OAuth tokens and securing communications with Zlib compression and AES encryption. The typical infection chain begins with a loader dubbed WMLOADER (often masquerading as a legitimate security executable) which decrypts a payload (wmsetup.log) and executes the backdoor in memory; additional capabilities include API hooking (Microsoft Detours), a custom PE loader (libPeConv-derived), and a 22-command handler architecture enabling file management, uploads/downloads, and remote execution while blending with normal cloud traffic to evade network detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.