NANOREMOTE, cousin of FINALDRAFT
ID: 2579bf34-f2f2-5289-b73f-ce2aa931d15b
STIX ID: report--2579bf34-f2f2-5289-b73f-ce2aa931d15b
Feed Name: Elastic Security Labs
Elastic Security Labs documents NANOREMOTE, a sophisticated 64-bit Windows backdoor delivered by a WMLOADER dropper; the implant implements 22 command handlers (discovery, command execution, custom PE loading in-memory and from disk) and abuses the Google Drive API for covert file staging and exfiltration. The report highlights code reuse with FINALDRAFT/REF7707, use of libPeConv and Microsoft Detours, includes YARA rules and file hashes, and provides detection guidance to defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
