Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Google Cloud to Deliver Remcos RAT

Hackers Exploit Google Cloud to Deliver Remcos RAT

Posted on April 15, 2026 By CWS

Cybercriminals have devised a new strategy to circumvent security measures by leveraging Google Cloud Storage for their malicious activities. This trusted platform is now being used to host phishing pages that deliver harmful malware, allowing attackers to bypass traditional email filters and web security tools without raising any alarms.

The campaign begins with phishing emails that direct recipients to pages hosted on storage.googleapis.com, a legitimate Google domain. These pages are cleverly designed to resemble Google Drive login screens, complete with branded logos and familiar document icons such as PDF, DOC, SHEET, and SLIDE. Unsuspecting victims are prompted to sign in to view a document, not realizing that their email credentials, including passwords and one-time passcodes, are being harvested.

Phishing Tactics and Malware Delivery

Once victims enter their credentials, they are deceived into downloading a JavaScript file labeled Bid-P-INV-Document.js, which serves as the starting point for the infection process. According to ANY.RUN’s Malware Trends Report for 2025, phishing campaigns utilizing trusted cloud hosting have surged, with remote access trojans increasing by 28% and backdoors by 68% year-on-year.

In April 2026, ANY.RUN’s team identified this specific attack, noting that subdomains such as pa-bids, com-bid, contract-bid-0, and out-bid were used to host malicious content. By using Google’s infrastructure, attackers achieve a level of immunity from reputation-based security filters traditionally used in email and web protection.

The Threat of Remcos RAT

The end goal of this campaign is the distribution of Remcos RAT, a remote access trojan that grants attackers extensive control over compromised systems. Once installed, it can log keystrokes, steal passwords, take screenshots, access microphones and webcams, monitor clipboard activity, and transfer files remotely. It embeds persistence in the Windows Registry under HKEY_CURRENT_USERSoftwareRemcos-{ID}, ensuring it survives reboots.

Not only do victims risk losing their Google account credentials, but they also unknowingly install a surveillance tool that operates silently on their devices. This combination of credential theft and remote access delivers attackers immediate and long-term access to compromised environments, turning a single phishing click into a significant security threat.

Layered Infection Strategy

The infection chain is intricately designed to evade detection at every stage. After executing the JavaScript file under Windows Script Host, a time-based evasion tactic delays execution to evade automated sandbox analysis. Subsequently, a Visual Basic Script fetches and runs additional scripts, dropping files into %APPDATA%WindowsUpdate and establishing startup persistence.

A PowerShell script named DYHVQ.ps1 then loads an obfuscated executable, ZIFDG.tmp, while an obfuscated .NET loader is fetched from Textbin, executing via memory to avoid antivirus detection. The .NET loader exploits RegSvcs.exe, a legitimate Microsoft tool, to inject the Remcos payload through process hollowing, evading endpoint protection.

Security professionals should approach storage.googleapis.com links with skepticism, treating them as potential threats. Behavioral analysis tools observing post-click activity prove more effective than relying solely on signature-based detection. Training employees, particularly in finance and leadership roles, to recognize phishing tactics and avoid unexpected file downloads is crucial.

Cyber Security News Tags:cloud hosting, cloud security, credential theft, Cybersecurity, email filters, Google Cloud, Malware, malware delivery, phishing attacks, Remcos RAT, remote access trojan, threat detection

Post navigation

Previous Post: Trump Advocates for Extending Surveillance Program Amid Privacy Concerns
Next Post: WordPress Plugins Compromised by Hidden Malware Backdoor

Related Posts

New PoC Exploit for Old PostgreSQL Vulnerability New PoC Exploit for Old PostgreSQL Vulnerability Cyber Security News
Critical Linux Kernel Bug Risks SSH Key Theft Critical Linux Kernel Bug Risks SSH Key Theft Cyber Security News
Miggo Security Named a Gartner® Cool Vendor in AI Security Miggo Security Named a Gartner® Cool Vendor in AI Security Cyber Security News
0-Click Zendesk Account Takeover Vulnerability Enables Access to all Zendesk Tickets 0-Click Zendesk Account Takeover Vulnerability Enables Access to all Zendesk Tickets Cyber Security News
New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials Cyber Security News
XenServer VM Tools for Windows Vulnerability Let Attackers Execute Arbitrary Code XenServer VM Tools for Windows Vulnerability Let Attackers Execute Arbitrary Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Resolves Windows 11 Update Issues with KB5089573
  • Critical GitLab Security Updates Address Key Vulnerabilities
  • Critical Flowise Vulnerability Exploit Code Released
  • Russian Spies Intensify Efforts to Acquire Western Tech
  • Introducing Pentest Swarm AI: Revolutionizing Autonomous Penetration Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Resolves Windows 11 Update Issues with KB5089573
  • Critical GitLab Security Updates Address Key Vulnerabilities
  • Critical Flowise Vulnerability Exploit Code Released
  • Russian Spies Intensify Efforts to Acquire Western Tech
  • Introducing Pentest Swarm AI: Revolutionizing Autonomous Penetration Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark