Attackers Abuse Microsoft Teams, Google Drive to Deliver Remote Access Malware
Key Takeaways A new attack campaign abuses legitimate enterprise platforms like Microsoft Teams and Google Drive to deploy the Nimbus RAT. The sophisticated campaign leverages social engineering,...
Key Takeaways
- A new attack campaign abuses legitimate enterprise platforms like Microsoft Teams and Google Drive to deploy the Nimbus RAT.
- The sophisticated campaign leverages social engineering, including email bombing and voice phishing via Teams, to trick users into granting remote access.
- Nimbus RAT utilizes Google Drive and Google Sheets for its command-and-control (C2) infrastructure, making detection challenging as traffic blends with normal cloud activity.
- Researchers observed a significant increase in suspicious Microsoft Teams interactions targeting organizations, particularly in the legal sector.
Cybersecurity researchers have uncovered a new, highly effective campaign in which threat actors are exploiting trusted enterprise collaboration tools such as Microsoft Teams and cloud storage services like Google Drive to distribute advanced remote access malware. This campaign leverages a blend of social engineering tactics and legitimate cloud infrastructure to remain undetected by conventional security measures.
Table Of Content
Sophisticated Attack Chain Unveiled
In early April 2026, eSentire’s Threat Response Unit (TRU) documented a targeted intrusion against a legal sector organization. The attack began with a Microsoft Teams voice phishing attempt, successfully manipulating a user into granting remote access through Windows Quick Assist. Within a mere 20 minutes, the attackers deployed Nimbus RAT, a Java-based Remote Access Trojan, completing the compromise.
The attack exhibited a well-orchestrated kill chain, indicative of the increasing operational sophistication of modern cyber campaigns. It commenced with an email bombing phase, where the victim’s inbox was inundated with over 280 legitimate subscription emails in a short timeframe. This tactic aimed to create confusion and a sense of urgency, preparing the ground for a subsequent fake IT helpdesk contact via Microsoft Teams.
Posing as internal IT support, the attacker convinced the user to initiate Quick Assist and follow instructions provided through a Pastebin link. The final malicious payload was delivered from a compromised Microsoft 365 tenant hosted on SharePoint, further enhancing the illusion of legitimacy. The downloaded archive contained a malicious Java archive, bundled with an OpenJDK runtime, enabling its execution on any Windows system regardless of pre-installed Java dependencies. Upon execution, Nimbus RAT established persistence and initiated encrypted communications with its command-and-control infrastructure.
Nimbus RAT: Blending into Cloud Ecosystems
A distinctive characteristic of Nimbus RAT is its innovative use of Google Drive and Google Sheets for its C2 channels. Rather than relying on traditional, easily identifiable malicious infrastructure, the malware communicates with legitimate Google APIs. This design choice makes network-level detection exceedingly difficult, as its traffic seamlessly integrates with typical enterprise cloud activity.
Commands are retrieved from attacker-controlled Google Drive files, and exfiltrated data is uploaded using the same method. Static analysis of Nimbus RAT reveals it to be a modular and highly capable implant, supporting arbitrary command execution, file system manipulation, registry access, screenshot capture, and in-memory execution of second-stage payloads. It also incorporates dual credential-harvesting mechanisms: a deceptive Windows Security prompt and direct API invocation via CredUIPromptForCredentialsW, both designed to capture multiple password attempts and improve success rates.
eSentire’s Threat Response Unit (TRU) telemetry indicates that this is not an isolated incident. “Researchers observed 1,540 suspicious Microsoft Teams interactions across 172 organizations over 12 months, with a sharp rise between December 2025 and March 2026,” eSentire Threat Response Unit stated in a report shared with Cybersecurity News. Nearly 65 percent of these attacks originated from disposable Microsoft 365 tenants utilizing onmicrosoft.com domains, frequently impersonating IT support or helpdesk personnel.
Infrastructure analysis highlights consistent attacker patterns, including rapid domain registration, the use of popular top-level domains (TLDs), reuse of hosting provider IP ranges, and the creation of numerous tenants for campaign scalability. In some instances, compromised legitimate tenants were also leveraged, boosting the credibility of phishing attempts and reducing user suspicion.
The broader implication of this campaign is a clear shift toward abusing trusted SaaS ecosystems at every stage of the attack lifecycle. Microsoft Teams is exploited for initial access, SharePoint for payload delivery, Pastebin for instruction staging, Quick Assist for remote control, and Google Drive for command-and-control. Since these widely used platforms cannot be easily blocked, defenders must prioritize behavioral detection and comprehensive cross-layer visibility.
What You Should Do
- Monitor for Unusual Mailbox Activity: Implement robust monitoring for sudden spikes in inbound email volume, as this often precedes voice phishing attempts.
- Enhance Endpoint Telemetry: Pay close attention to endpoint telemetry, specifically identifying suspicious execution of
javaw.exefrom non-standard directories and correlating it with outbound connections to Google APIs. - Implement Context-Aware Detection: Develop and deploy security strategies that focus on user behavior, process activity, and identity signals, moving beyond domain-based blocking alone.
- Strengthen User Training: Conduct regular security awareness training emphasizing the risks of social engineering, especially voice phishing and requests for remote access via tools like Quick Assist.
- Review Cloud Service Configurations: Regularly audit and secure configurations for Microsoft 365, Google Workspace, and other SaaS platforms to minimize potential abuse by attackers.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.