Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors used Microsoft Teams voice phishing (vishing) to deceive the victim into granting remote access via Quick Assist, then deployed a Java-based remote access trojan (RAT). TRU tracks this malware as Nimbus RAT.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Nimbus RAT can display either a Java Swing imitation of the Windows Security credential prompt or invoke the real Windows CredUIPromptForCredentialsW API directly via JNA ... Both approaches are designed to capture two password entries
Nimbus RAT is a modular and highly capable implant... A defining feature of Nimbus RAT is its use of Google Drive and Google Sheets as C2 channels. | the malware communicates with legitimate Google APIs, making network-level detection extremely difficult
All command delivery and data exfiltration travels over legitimate Google API endpoints.
Commands are fetched from attacker-controlled Google Drive files, and exfiltrated data is uploaded in the same way.
The final payload was retrieved from a compromised Microsoft 365 tenant hosted on SharePoint
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Java-based modular remote access trojan delivered via Quick Assist and a SharePoint-hosted archive. It establishes persistence, uses encrypted communications, abuses Google Drive and Google Sheets as command-and-control channels, supports arbitrary command execution, file system and registry access, screenshot capture, in-memory second-stage payload execution, and credential harvesting via fake Windows Security prompts and CredUIPromptForCredentialsW.
A Java-based remote access backdoor used after Microsoft Teams vishing attacks. It establishes persistence on endpoints and uses Google Drive and Google Sheets for command-and-control to blend malicious traffic with benign cloud activity.
Java-based remote access trojan used after Teams vishing and Quick Assist access. It bundles its own OpenJDK runtime, uses Google Drive and Google Sheets/Google APIs for command-and-control, supports shell execution, file operations, registry access, screenshots, credential theft via fake or native Windows prompts, and in-memory second-stage Java code execution. It does not autonomously install persistence; operators stage persistence separately.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.