NANOREMOTE Malware Exploits Google Drive API for C2 on Windows Systems

NANOREMOTE Malware Exploits Google Drive API for C2 on Windows Systems

First seen 12 Dec 2025, 12:53 UTC ThehackernewsCybersecuritynewsGbhackers 37.6

Article Content

Browse articles
ThreatCluster

In October 2025, a new Windows backdoor named NANOREMOTE was identified, utilizing the Google Drive API for its Command-and-Control (C2) operations. This malware presents a significant risk to enterprise environments by disguising its malicious traffic within legitimate cloud infrastructure, making detection challenging.