NANOREMOTE is a 64-bit Windows backdoor identified in 2025 and assessed to share a development lineage with the FINALDRAFT (Squidoor) implant associated with the REF7707 espionage ecosystem. It performs host reconnaissance, executes operator commands through Windows command-shell processes, manages files and directories, and loads additional PE payloads from disk or directly from memory. NANOREMOTE can collect system, user, process, privilege, network, and disk information.
The backdoor uses encrypted and compressed HTTP communications and can use the Google Drive API for command-and-control tasking, payload staging, and bidirectional file transfers. Google Drive transfer tasks can be queued, paused, resumed, and cancelled. It uses OAuth configuration to access cloud storage and thereby blends malicious transfer activity with legitimate cloud-service traffic.
Observed deployments used the WMLOADER loader, which masquerades as security software and decrypts the backdoor for in-memory execution. NANOREMOTE also incorporates manual PE mapping functionality derived from libPeConv and Microsoft Detours hooks for process- and thread-termination functions, improving payload execution flexibility and process resiliency. Its initial-access vector has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The shellcode is located at RVA (0x193041) and decrypted using a rolling XOR algorithm... wmsetup.log... [is decrypted] using AES-CBC.
Uses WSAIoctl with SIO_GET_INTERFACE_LIST to retrieve internal and external IP address.
Grabs username via GetUserNameW... Checks if current user is member of Administrator group via IsUserAnAdmin.
Handler #1... retrieves the hostname... operating-system information... process path... [and] process ID of running program.
Handler #4 - List folder contents by path... includes whether the item is a directory... hidden... last modified date, file name [and] size. | Handler #6... uses GetLogicalDrives, GetDiskFreeSpaceExW, GetDriveTypeW, [and] GetVolumeInformationW to collect storage disk information.
These requests occur over HTTP where the JSON data is submitted through POST requests... The URI for all requests use /api/client with User-Agent (NanoRemote/1.0).
"NANOREMOTE... uses the Google Drive API for command-and-control (C2)... similarities with... FINALDRAFT... employs Microsoft Graph API for C2"
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows backdoor using Google Drive API for C2; shares code similarities with FINALDRAFT.
A backdoor/RAT that leverages the Google Drive API as a channel for file transfer (upload/download) between the operator infrastructure and the compromised host, likely to blend with legitimate cloud traffic.
NANOREMOTE is a backdoor malware that uses the Google Drive API for covert command and control (C2) communications. It is linked to the FINALDRAFT espionage group.
NANOREMOTE is a stealthy malware that uses Google Drive as its command and control (C2) channel, allowing attackers to remotely access and control infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.