HomeSecurityNANOREMOTE malware abuses Google Drive API

NANOREMOTE malware abuses Google Drive API

Cybersecurity researchers have revealed details of a new fully-featured Windows backdoor called NANOREMOTE, which uses the Google Drive API for command and control (C2) purposes. According to a report from Elastic Security Labs, the malware shares code similarities with another implant codenamed FINALDRAFT (also known as Squidoor) that uses the Microsoft Graph API for C2.

See also: Amos malware distributed via Google Ads – How are ChatGPT & Grok involved?

NANOREMOTE
NANOREMOTE malware abuses Google Drive API

FINALDRAFT is attributed to a threat group known as REF7707 (also known as CL-STA-0049, Earth Alux, and Jewelbug). “One of the main features of the malware focuses on transferring data to and from the victim using the Google Drive API,” said Daniel Stepanic, principal security researcher at Elastic Security Labs.

REF7707 is believed to be a suspected Chinese-based activity group that has targeted governments, defense, telecommunications, education, and aviation sectors in Southeast Asia and South America since March 2023, according to Palo Alto Networks Unit 42.

In October 2025, Symantec, owned by Broadcom, attributed a five-month-long hack targeting a Russian provider . The exact initial means of access used to deliver NANOREMOTE is currently unknown. However, the observed attack chain involves a loader named WMLOADER that mimics a Bitdefender error handling component (“BDReinit.exe”) and decrypts shellcode responsible for launching the backdoor.

See also: FvncBot: New Android banking malware steals data

NANOREMOTE malware abuses Google Drive API

Written in C++, NANOREMOTE is equipped to perform reconnaissance, file and command execution, and file transfer to and from victims' environments using the Google Drive API. It is also preconfigured to communicate with a hardcoded, non-routable IP address over HTTP to process requests sent by the operator and send the response back.

“The URI for all requests uses /api/client with User-Agent (NanoRemote/1.0).” Its main functionality is realized through a set of 22 command handlers that allow it to collect host information, perform file and directory operations, execute portable executables (PE) already on disk, clear the cache, download/upload files to Google Drive, pause/resume/cancel data transfers, and terminate itself.

See also: Phishing or malware: Which is the bigger threat to corporate users?

NANOREMOTE malware abuses Google Drive API

Elastic reported that it detected an object (“wmsetup.log”) uploaded to VirusTotal from the Philippines on October 3, 2025, that can be decrypted by WMLOADER with the same 16-byte key to reveal a FINALDRAFT implant, indicating that the two malware families are likely the work of the same threat actor. It is unclear why the same hardcoded key is used in both.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS