Skip to content
NANOREMOTE Malware Exploits Google Drive API for C2 on Windows Systems

NANOREMOTE Malware Exploits Google Drive API for C2 on Windows Systems

First seen 12 Dec 2025, 12:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

In October 2025, a new Windows backdoor named NANOREMOTE was identified, utilizing the Google Drive API for its Command-and-Control (C2) operations. This malware presents a significant risk to enterprise environments by disguising its malicious traffic within legitimate cloud infrastructure, making detection challenging.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track Nanoremote in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed