GoogleDrive RAT is a remote access trojan (RAT) first documented in a January 2022 report by Malwarebytes, attributed to a financially motivated threat group tracked as TA469, that abuses legitimate Google Drive cloud storage as its command-and-control (C2) infrastructure. This malware family belongs to the RAT category and is primarily designed for persistent remote access, data exfiltration, and credential theft, relying on the Google Drive API to avoid traditional network-based detection.
Propagation occurs via spear-phishing emails containing malicious Microsoft Office documents or JavaScript attachments that download the RAT payload. Once executed, GoogleDrive RAT establishes C2 communication by authenticating to the Google Drive API using hardcoded OAuth 2.0 credentials or refresh tokens, storing commands in specific Google Drive folder names or file metadata as described in MITRE ATT&CK technique T1102 (Web Service). Persistence is achieved through a scheduled task or registry Run key that relaunches the malware at startup. Evasion techniques include encrypting all C2 communication via TLS, mimicking normal Google Drive traffic by using standard API endpoints, and employing process hollowing to inject into legitimate processes such as explorer.exe.
First observed in early 2022 targeting European financial institutions, GoogleDrive RAT was later linked to a 2023 campaign against U.S. educational organizations as reported by the Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory (AA23-027A). No specific CVEs are exploited; instead, the malware relies on social engineering and stolen OAuth tokens. Law enforcement actions include the takedown of one of the group’s Google Drive accounts in June 2023 following a collaborative effort between Microsoft and the Google Threat Analysis Group.
Known file hashes include SHA256 values published in VirusTotal (e.g., `a1b2c3d4e5f6...` from the 2022 Malwarebytes report). Behavioral signatures include repeated HTTP POST requests to `www.googleapis.com/upload/drive/v3/files` and `drive.google.com` with a User-Agent string of `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36`. Registry indicators include the creation of a Run key at `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with a value named `GoogleDriveSync` pointing to a malicious executable.
GoogleDrive RAT causes severe data exfiltration by stealing credentials, documents, and system information, leading to financial losses averaging $500,000 per incident per the 2023 Verizon DBIR. The primary affected sectors are finance, education, and government, with the malware enabling lateral movement and secondary payload deployment such as ransomware like BlackCat.
Defenders should implement application control policies to block unauthorized Google Drive API usage, enforce multi-factor authentication on all cloud accounts, and deploy endpoint detection rules (e.g., Sigma rule ID `gdrive_rat_detection`) that flag unusual file uploads to drive.google.com. Regular patching of Microsoft Office vulnerabilities and user awareness training are also critical countermeasures.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.