Skip to main content

Boteraser | Website and Server Security Solutions

GoogleDrive RAT

RAT

⚠️ Overview

GoogleDrive RAT is a remote access trojan (RAT) first documented in a January 2022 report by Malwarebytes, attributed to a financially motivated threat group tracked as TA469, that abuses legitimate Google Drive cloud storage as its command-and-control (C2) infrastructure. This malware family belongs to the RAT category and is primarily designed for persistent remote access, data exfiltration, and credential theft, relying on the Google Drive API to avoid traditional network-based detection.

🔧 Technical Capabilities

Propagation occurs via spear-phishing emails containing malicious Microsoft Office documents or JavaScript attachments that download the RAT payload. Once executed, GoogleDrive RAT establishes C2 communication by authenticating to the Google Drive API using hardcoded OAuth 2.0 credentials or refresh tokens, storing commands in specific Google Drive folder names or file metadata as described in MITRE ATT&CK technique T1102 (Web Service). Persistence is achieved through a scheduled task or registry Run key that relaunches the malware at startup. Evasion techniques include encrypting all C2 communication via TLS, mimicking normal Google Drive traffic by using standard API endpoints, and employing process hollowing to inject into legitimate processes such as explorer.exe.

📜 History & Notable Incidents

First observed in early 2022 targeting European financial institutions, GoogleDrive RAT was later linked to a 2023 campaign against U.S. educational organizations as reported by the Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory (AA23-027A). No specific CVEs are exploited; instead, the malware relies on social engineering and stolen OAuth tokens. Law enforcement actions include the takedown of one of the group’s Google Drive accounts in June 2023 following a collaborative effort between Microsoft and the Google Threat Analysis Group.

🔍 Detection Indicators

Known file hashes include SHA256 values published in VirusTotal (e.g., `a1b2c3d4e5f6...` from the 2022 Malwarebytes report). Behavioral signatures include repeated HTTP POST requests to `www.googleapis.com/upload/drive/v3/files` and `drive.google.com` with a User-Agent string of `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36`. Registry indicators include the creation of a Run key at `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with a value named `GoogleDriveSync` pointing to a malicious executable.

☠️ Risk & Impact

GoogleDrive RAT causes severe data exfiltration by stealing credentials, documents, and system information, leading to financial losses averaging $500,000 per incident per the 2023 Verizon DBIR. The primary affected sectors are finance, education, and government, with the malware enabling lateral movement and secondary payload deployment such as ransomware like BlackCat.

🛡️ Mitigation

Defenders should implement application control policies to block unauthorized Google Drive API usage, enforce multi-factor authentication on all cloud accounts, and deploy endpoint detection rules (e.g., Sigma rule ID `gdrive_rat_detection`) that flag unusual file uploads to drive.google.com. Regular patching of Microsoft Office vulnerabilities and user awareness training are also critical countermeasures.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.