logo

New Phishing Campaign Exploits Google Storage to Deliver Remcos RAT

ID: f67b497e-685b-5c7d-99c5-9d2949614843

STIX ID: report--f67b497e-685b-5c7d-99c5-9d2949614843

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Phishing campaign using Google Cloud Storage to host a fake Google Drive login page that captures credentials and OTPs, then delivers the Remcos RAT through a multi‑stage script chain (JS → VBS → PowerShell) and an in‑memory .NET loader that hollowes a signed RegSvcs.exe for stealth and persistence; defenders are advised to rely on behavioral EDR, monitor script chains and atypical RegSvcs.exe execution paths, and reinforce user awareness.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.