logo

NANOREMOTE, cousin of FINALDRAFT

ID: 2579bf34-f2f2-5289-b73f-ce2aa931d15b

STIX ID: report--2579bf34-f2f2-5289-b73f-ce2aa931d15b

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2025-12-11

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents NANOREMOTE, a sophisticated 64-bit Windows backdoor delivered by a WMLOADER dropper; the implant implements 22 command handlers (discovery, command execution, custom PE loading in-memory and from disk) and abuses the Google Drive API for covert file staging and exfiltration. The report highlights code reuse with FINALDRAFT/REF7707, use of libPeConv and Microsoft Detours, includes YARA rules and file hashes, and provides detection guidance to defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.