Attackers Are Exploiting Microsoft Teams and Google Drive to Deploy Malware — Compromise in Less Than 20 Minutes

5.6.2026 | Autor: Top privacy
4

Attackers are exploiting Microsoft Teams, SharePoint, and Google Drive to deploy the Nimbus RAT. A corporate endpoint can be compromised in less than 20 minutes—find out how to defend against it.

Attackers Are Exploiting Microsoft Teams and Google Drive to Deploy Malware — Compromise in Less Than 20 Minutes

What the attack looks like in practice

The campaign begins with so-called “email bombing”—the victim receives hundreds of legitimate subscription emails in a short period of time, creating chaos and a sense of urgency. Shortly thereafter, the attacker contacts the victim via Microsoft Teams, posing as an internal IT staff member or help desk representative. The attacker convinces the victim to launch Windows Quick Assist and grant remote access to their device.

The final payload—a Java-based remote access trojan called Nimbus RAT—is downloaded by the attacker from the SharePoint of a compromised Microsoft 365 tenant. This maintains the illusion of legitimacy, since the traffic originates from a trusted corporate storage repository. Once launched, the malware establishes encrypted communication with its C2 infrastructure—and that infrastructure consists not of any suspicious servers, but of Google Drive and Google Sheets.

Why This Attack Is Extremely Difficult to Detect

Nimbus RAT does not communicate via traditional malicious infrastructure. It retrieves commands from attacker-controlled files on Google Drive and uploads exfiltrated data in the same way. The result is network traffic that, at first glance, is indistinguishable from normal corporate cloud activity.

The malware is modular and supports the execution of arbitrary commands, file system manipulation, registry access, screenshot capture, and in-memory execution of additional payloads. It also includes a dual mechanism for stealing login credentials—a fake Windows Security window and a direct call to the system API.

Scope of the Campaign

eSentire’s telemetry recorded 1,540 suspicious Teams interactions across 172 organizations over a 12-month period, with a significant increase observed between December 2025 and March 2026. Nearly 65% of the attacks originated from throwaway Microsoft 365 tenants using onmicrosoft.com domains that impersonated IT support. In some cases, the attackers also exploited legitimate compromised tenants, which further increased the credibility of the communications.

One of the primary targets was an organization in the legal sector—which is no coincidence. Law firms handle sensitive client data and are among the preferred targets of financially motivated attackers.

What This Means in Practice

Throughout its entire course, the attack does not exploit any technical vulnerabilities—it relies exclusively on social engineering and employees’ trust in internal tools. Microsoft Teams, SharePoint, Google Drive—these are platforms that organizations cannot simply block. Defense must therefore be based on behavioral detection, not domain blocking.

Specific recommendations: restrict or disable Quick Assist outside the IT team’s environment, monitor sudden spikes in email volume in inboxes, track the execution of javaw.exe from non-standard directories, and deploy an EDR solution with behavioral detection capable of correlating activity across layers.

From the perspective of GDPR and NIS2, it is important to note that the compromise of an endpoint with access to corporate or client data constitutes a potential security incident that requires an assessment of the obligation to notify the Slovak Data Protection Authority.


OUR SERVICES
Source: Cyber Security News


Top privacy

Top privacy

"High-quality content isn't created by copywriters, but by experts."