216.73.216.6

Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT

· Published 30/05/2026 11:25 · Modified 02/06/2026 10:00

Export JSON

Essential information

Published
30/05/2026 11:25
Modified
02/06/2026 10:00
Tags
2026-05-30 email bombing google drive c2 java rat microsoft teams nimbus rat quick assist social engineering vishing
Related entities
3 observables, 30 techniques (mitre), 1 malware, 8 others

Description

In April 2026, threat actors deployed against a legal industry target using voice phishing. The attack began with (282 emails in 90 minutes), followed by a fake IT helpdesk contact via Teams who convinced the victim to grant remote access. Within 20 minutes, a Java-based RAT was deployed that uses Google Drive and Google Sheets for command-and-control, making network traffic appear benign. Analysis of 1,540 suspicious Teams messages across 172 customer environments over 12 months revealed 65% originated from throwaway onmicrosoft.com tenants with IT-themed names. The malware bundles its own Java runtime, implements two credential theft mechanisms, and allows in-memory second-stage code execution. Post-compromise targeting included Signal Desktop attachments and Outlook mailboxes.

External references