NANOREMOTE Malware Leverages Google Drive API for Command-and-Control (C2) to Attack Windows Systems
ID: c3bb26c5-d210-5960-97e4-b7e985c43c7e
STIX ID: report--c3bb26c5-d210-5960-97e4-b7e985c43c7e
Feed Name: cybersecurityNews.com
NANOREMOTE is a sophisticated Windows backdoor that leverages Google Drive API as a covert C2 channel, authenticating via hard-coded OAuth tokens and securing communications with Zlib compression and AES encryption. The typical infection chain begins with a loader dubbed WMLOADER (often masquerading as a legitimate security executable) which decrypts a payload (wmsetup.log) and executes the backdoor in memory; additional capabilities include API hooking (Microsoft Detours), a custom PE loader (libPeConv-derived), and a 22-command handler architecture enabling file management, uploads/downloads, and remote execution while blending with normal cloud traffic to evade network detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
