logo

Google's Cloud Run Service Spreads Several Bank Trojans

ID: 037a4418-5e37-597c-af51-d0eeecddc7b8

STIX ID: report--037a4418-5e37-597c-af51-d0eeecddc7b8

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-20

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Cisco Talos observed a surge in phishing campaigns (since Sept 2023) that abuse Google Cloud Run to host malicious installers and drop banking Trojans—including Astaroth, Mekiotio, and Ousaban—targeting over 300 institutions across 15 Latin American countries and increasingly spreading into Europe and North America; the campaigns use invoice/tax-themed lures, cloaking (e.g. geoplugin checks), and shared cloud infrastructure, and the report provides IOCs and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.