logo

Hackers abuse Google Cloud Run in massive banking trojan campaign

ID: 51c78634-1137-5ffd-8425-48f1443df562

STIX ID: report--51c78634-1137-5ffd-8425-48f1443df562

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed a large-scale campaign abusing Google Cloud Run to host phishing links and distribute banking trojans (Astaroth, Mekotio, Ousaban) that target financial institutions across Latin America; delivery uses malicious MSI installers or redirects to Cloud Storage, BITSAdmin for second-stage payloads, and persistence via Startup LNK files executing AutoIT, enabling credential theft (keylogging, screen capture, clipboard monitoring) and evasion—Google has removed offending links and is reviewing mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.