NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems
Cybersecurity researchers have revealed information about NANOREMOTE, a brand-new, fully functional Windows backdoor that employs the Google Drive API for command-and-control (C2) functions.
A report from Elastic Security Labs claims that the malware's code is comparable to that of another implant called FINALDRAFT (also known as Squidoor), which uses the Microsoft Graph API for C2. FINALDRAFT is linked to the REF7707 threat cluster (also known as CL-STA-0049, Earth Alux, and Jewelbug).
According to Daniel Stepanic, chief security researcher at Elastic Security Labs, one of the main characteristics of the malware is its ability to transfer data back and forth from the victim endpoint via the Google Drive API.
In the end, this feature creates a difficult-to-detect conduit for payl...

