Elastic detects stealthy NANOREMOTE malware using Google Drive as C2
securityaffairs.com·3d
💿WORM Storage
Preview
Report Post

Pierluigi Paganini December 12, 2025

Elastic found a new Windows backdoor, NANOREMOTE, similar to FINALDRAFT/REF7707, using the Google Drive API for C2.

Elastic Security Labs researchers uncovered NANOREMOTE, a new Windows backdoor that uses the Google Drive API for C2. Elastic says it shares code with the FINALDRAFT (Squidoor) implant, which uses Microsoft Graph API and is linked to threat group [REF7707](https://securityaffairs.com/183488/apt/china-l…

Similar Posts

Loading similar posts...