Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
August 4, 2026
OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks
August 4, 2026
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
Home/CyberSecurity News/Attackers Abuse Microsoft Teams, Google Drive to Deliver Remote Access Malware
CyberSecurity News

Attackers Abuse Microsoft Teams, Google Drive to Deliver Remote Access Malware

Key Takeaways A new attack campaign abuses legitimate enterprise platforms like Microsoft Teams and Google Drive to deploy the Nimbus RAT. The sophisticated campaign leverages social engineering,...

Sarah simpson
Sarah simpson
June 4, 2026 4 Min Read
55 0

Key Takeaways

  • A new attack campaign abuses legitimate enterprise platforms like Microsoft Teams and Google Drive to deploy the Nimbus RAT.
  • The sophisticated campaign leverages social engineering, including email bombing and voice phishing via Teams, to trick users into granting remote access.
  • Nimbus RAT utilizes Google Drive and Google Sheets for its command-and-control (C2) infrastructure, making detection challenging as traffic blends with normal cloud activity.
  • Researchers observed a significant increase in suspicious Microsoft Teams interactions targeting organizations, particularly in the legal sector.

Cybersecurity researchers have uncovered a new, highly effective campaign in which threat actors are exploiting trusted enterprise collaboration tools such as Microsoft Teams and cloud storage services like Google Drive to distribute advanced remote access malware. This campaign leverages a blend of social engineering tactics and legitimate cloud infrastructure to remain undetected by conventional security measures.

Table Of Content

  • Key Takeaways
  • Sophisticated Attack Chain Unveiled
  • Nimbus RAT: Blending into Cloud Ecosystems
  • What You Should Do

Sophisticated Attack Chain Unveiled

In early April 2026, eSentire’s Threat Response Unit (TRU) documented a targeted intrusion against a legal sector organization. The attack began with a Microsoft Teams voice phishing attempt, successfully manipulating a user into granting remote access through Windows Quick Assist. Within a mere 20 minutes, the attackers deployed Nimbus RAT, a Java-based Remote Access Trojan, completing the compromise.

The attack exhibited a well-orchestrated kill chain, indicative of the increasing operational sophistication of modern cyber campaigns. It commenced with an email bombing phase, where the victim’s inbox was inundated with over 280 legitimate subscription emails in a short timeframe. This tactic aimed to create confusion and a sense of urgency, preparing the ground for a subsequent fake IT helpdesk contact via Microsoft Teams.

Posing as internal IT support, the attacker convinced the user to initiate Quick Assist and follow instructions provided through a Pastebin link. The final malicious payload was delivered from a compromised Microsoft 365 tenant hosted on SharePoint, further enhancing the illusion of legitimacy. The downloaded archive contained a malicious Java archive, bundled with an OpenJDK runtime, enabling its execution on any Windows system regardless of pre-installed Java dependencies. Upon execution, Nimbus RAT established persistence and initiated encrypted communications with its command-and-control infrastructure.

Nimbus RAT: Blending into Cloud Ecosystems

A distinctive characteristic of Nimbus RAT is its innovative use of Google Drive and Google Sheets for its C2 channels. Rather than relying on traditional, easily identifiable malicious infrastructure, the malware communicates with legitimate Google APIs. This design choice makes network-level detection exceedingly difficult, as its traffic seamlessly integrates with typical enterprise cloud activity.

Commands are retrieved from attacker-controlled Google Drive files, and exfiltrated data is uploaded using the same method. Static analysis of Nimbus RAT reveals it to be a modular and highly capable implant, supporting arbitrary command execution, file system manipulation, registry access, screenshot capture, and in-memory execution of second-stage payloads. It also incorporates dual credential-harvesting mechanisms: a deceptive Windows Security prompt and direct API invocation via CredUIPromptForCredentialsW, both designed to capture multiple password attempts and improve success rates.

eSentire’s Threat Response Unit (TRU) telemetry indicates that this is not an isolated incident. “Researchers observed 1,540 suspicious Microsoft Teams interactions across 172 organizations over 12 months, with a sharp rise between December 2025 and March 2026,” eSentire Threat Response Unit stated in a report shared with Cybersecurity News. Nearly 65 percent of these attacks originated from disposable Microsoft 365 tenants utilizing onmicrosoft.com domains, frequently impersonating IT support or helpdesk personnel.

Infrastructure analysis highlights consistent attacker patterns, including rapid domain registration, the use of popular top-level domains (TLDs), reuse of hosting provider IP ranges, and the creation of numerous tenants for campaign scalability. In some instances, compromised legitimate tenants were also leveraged, boosting the credibility of phishing attempts and reducing user suspicion.

The broader implication of this campaign is a clear shift toward abusing trusted SaaS ecosystems at every stage of the attack lifecycle. Microsoft Teams is exploited for initial access, SharePoint for payload delivery, Pastebin for instruction staging, Quick Assist for remote control, and Google Drive for command-and-control. Since these widely used platforms cannot be easily blocked, defenders must prioritize behavioral detection and comprehensive cross-layer visibility.

What You Should Do

  • Monitor for Unusual Mailbox Activity: Implement robust monitoring for sudden spikes in inbound email volume, as this often precedes voice phishing attempts.
  • Enhance Endpoint Telemetry: Pay close attention to endpoint telemetry, specifically identifying suspicious execution of javaw.exe from non-standard directories and correlating it with outbound connections to Google APIs.
  • Implement Context-Aware Detection: Develop and deploy security strategies that focus on user behavior, process activity, and identity signals, moving beyond domain-based blocking alone.
  • Strengthen User Training: Conduct regular security awareness training emphasizing the risks of social engineering, especially voice phishing and requests for remote access via tools like Quick Assist.
  • Review Cloud Service Configurations: Regularly audit and secure configurations for Microsoft 365, Google Workspace, and other SaaS platforms to minimize potential abuse by attackers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Comodo Internet Security Flaw Lets Attackers Crash Windows Systems

Next Post

Critical WordPress Plugin Bug Actively Exploited to Inject PHP Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Roblox Malware Steals Desktop Streams and Webcam Footage
August 4, 2026
Keyv npm package compromised in supply chain attack
August 4, 2026
Cybercriminals Exploit ChatGPT for Scam Operations, OpenAI Reports
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us