Hackers Abuse Google Cloud Storage to Slip Remcos RAT Past Email Filters
ID: c5af9def-904a-5963-9a16-ec6260486e86
STIX ID: report--c5af9def-904a-5963-9a16-ec6260486e86
Feed Name: GBHackers
Researchers document a phishing campaign that leverages Google Cloud Storage and Google Drive–style lures to bypass email and web filters and deliver the Remcos remote access trojan. The multi‑stage, mostly fileless chain uses a downloadable JavaScript that spawns VBS and PowerShell stages, loads an obfuscated .NET loader in memory, and abuses a signed Microsoft binary (RegSvcs.exe) for process hollowing, resulting in persistence (e.g., HKEY_CURRENT_USER\Software\Remcos-{ID}), encrypted C2, and high evasiveness against reputation and static‑hash defenses; the report advocates behavior‑based detection, interactive sandboxing, and IOC operationalization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
