FINALDRAFT is an espionage-focused threat actor linked to the NANOREMOTE backdoor. The group has been associated with cyber espionage activity and the use of covert command-and-control techniques that blend malicious traffic with legitimate cloud-service usage. In observed activity, malware attributed to the group used the Google Drive API for command-and-control, indicating an emphasis on stealth and defense evasion through abuse of trusted online services. Publicly available information in this context is limited; no high-confidence attribution to a specific country, victim geography, or industry sector is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.