Threat reportPhishingTL-2026-0409
Remcos RAT Phishing Campaign Abusing Google Cloud Storage (storage.googleapis.com) with RegSvcs.exe Process Hollowing
Remcos RAT Phishing Campaign Abusing Google Cloud Storage (TL-2026-0409), also tracked as Bid-Lure Remcos Campaign, is a high-severity phishing campaign, first published 2026-04-22. It has no confirmed attribution, affects Microsoft Windows (all supported SKUs), maps to 21 MITRE ATT&CK techniques (T1027, T1036.004, T1041), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0409
- Threat ID
- TL-2026-0409
- Also known as
- Bid-Lure Remcos Campaign, Google Cloud Storage Remcos Phish, GCS Drive Phish
- Severity
- HIGH
- Status
- MONITORING
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- financial, government, construction, manufacturing, legal, professional-services, energy, healthcare
- Target regions
- North America, Europe, Latin America, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Remcos RAT Phishing Campaign Abusing Google Cloud Storage
Malware and tooling: Remcos, Remcos RAT v4.x, RegSvcs.exe, Remcos RAT C2 (TCP 2404), wscript.exe
How Remcos RAT Phishing Campaign Abusing Google Cloud Storage works
ANY.RUN, Cybersecurity News, and GBHackers have disclosed an active phishing campaign abusing storage.googleapis.com buckets (pa-bids, com-bid, contract-bid-0, in-bids, out-bid) to host fake Google Drive login pages and deliver Remcos RAT. The multi-stage chain uses a JScript bait (Bid-Packet-INV-Document.js), PowerShell downloader (DYHVQ.ps1), and a binary loader (ZIFDG.tmp) that process-hollows the signed Microsoft .NET utility RegSvcs.exe to run Remcos in memory. Abuse of trusted Google infrastructure bypasses DMARC/SPF/DKIM checks and URL-reputation email gateways; C2 beacons to 198.187.29.19.
Overview -------- In April 2026, ANY.RUN, Cybersecurity News, GBHackers, and Cyberpress published analyses of an ongoing Remcos RAT phishing campaign that abuses Google Cloud Storage (storage.googleapis.com) to host intermediate payloads and fake Google Drive sign-in pages. The campaign is not a new vulnerability; it is a weaponization of trusted SaaS hosting for payload delivery and credential theft, coupled with a signed-binary-proxy execution chain that terminates in process hollowing of RegSvcs.exe (the Microsoft .NET Services Installation utility).
Delivery and Lure ----------------- Victims receive business-themed lures (invoices, bid packets, contract attachments) that link to storage.googleapis.com URLs such as storage.googleapis.com/com-bid/GoogleDrive.html and storage.googleapis.com/pa-bids/*. Because storage.googleapis.com is a Google-owned domain with a valid TLS certificate and high reputation score, URL-reputation email security gateways and browser SmartScreen-style reputation engines do not flag the links. The HTML page renders a pixel-accurate clone of the Google Drive login experience. Submitted credentials are exfiltrated to an attacker-controlled endpoint, after which the page serves a JScript file named Bid-Packet-INV-Document.js (archived inside a ZIP with a document-lookalike icon).
Stage 1 - JScript Dropper ------------------------- When the victim double-clicks the .js file, wscript.exe is invoked. The JScript is heavily obfuscated (string concatenation, base64-encoded blobs, character-code reconstruction) and resolves to a PowerShell command executed via powershell.exe -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden. This stage maps to T1059.005 (Visual Basic / JScript) and T1027 (Obfuscated Files or Information).
Stage 2 - PowerShell Downloader ------------------------------- The PowerShell stage (observed file DYHVQ.ps1) downloads an encrypted binary blob from another storage.googleapis.com bucket (contract-bid-0, in-bids, out-bid rotated), writes it to %APPDATA%\WindowsUpdate\ZIFDG.tmp, decodes it with a simple XOR/AES routine (T1140 Deobfuscate / Decode Files), and executes it. Persistence is installed via HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run (T1547.001 Registry Run Keys).
Stage 3 - RegSvcs.exe Process Hollowing --------------------------------------- The ZIFDG.tmp loader spawns a suspended instance of the signed Microsoft binary RegSvcs.exe (%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe), unmaps its image, writes the Remcos RAT PE into the cleared memory region using NtUnmapViewOfSection + WriteProcessMemory + SetThreadContext + ResumeThread, and resumes execution. This matches T1055.012 (Process Hollowing) and T1218 (Signed Binary Proxy Execution) via the trusted .NET utility. Because RegSvcs.exe is Microsoft-signed and whitelisted by most EDR reputation engines, behavioural signatures rather than reputation must catch the execution.
Remcos RAT Post-Exploitation ---------------------------- Remcos is a commercial Remote Control and Surveillance tool sold by Germany-based Breaking Security, widely abused by cybercrime actors since 2016. Capabilities observed in this campaign: keylogging (T1056.001), screenshot capture, credential theft from browsers (T1555.003), clipboard monitoring (T1056.004), and file exfiltration over the C2 channel (T1041 Exfiltration Over C2 Channel). The Remcos configuration beacons to 198.187.29.19 on TCP 2404 (the default Remcos port range). A Remcos identifier registry key is dropped at HKEY_CURRENT_USER\Software\Remcos-{random 8-char ID}.
Infrastructure Abuse -------------------- Five Google Cloud Storage buckets have been identified as weaponized: pa-bids, com-bid, contract-bid-0, in-bids, out-bid. Bucket names mimic procurement / bidding vocabulary to blend with the business lure. Google's abuse response typically removes reported buckets within 24-72 hours, but the operator rotates to freshly provisioned buckets using the same naming pattern. This matches T1583.006 (Acquire Infrastructure: Web Services) and T1102 (Web Service) as alternate TTP mappings.
Why This Campaign Matters ------------------------- (1) Email security bypass: storage.googleapis.com inherits Google's TLS cert, DMARC/SPF/DKIM alignment, and reputation; most Secure Email Gateways allowlist *.googleapis.com. (2) Signed-binary-proxy execution: RegSvcs.exe is a LOLBAS entry already; pairing it with process hollowing defeats application-allowlisting solutions that trust Microsoft-signed binaries by hash or publisher. (3) Remcos RAT is under active commodity-malware use by multiple distinct operators (FIN7 affiliates, UNC-designated clusters, and independent criminal crews), so attribution is deliberately left as Unknown commodity-malware operators.
Defender Priorities ------------------- - Block or alert on *.storage.googleapis.com URLs carrying executable, archive, or script MIME types at the proxy / SEG layer. - Hunt for RegSvcs.exe child / network activity (it should virtually never make outbound TCP connections or be a parent of unusual processes in a typical enterprise). - Alert on HKCU\Software\Remcos-* registry key creation. - Deploy ASR rule 'Block JavaScript or VBScript from launching downloaded executable content' (GUID D3E037E1-3EB8-44C8-A917-57927947596D).
MITRE ATT&CK techniques used in TL-2026-0409
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerading: Masquerade Task or Service; T1055.012 Process Injection: Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
Exfiltration
T1041 Exfiltration Over C2 Channel
Collection
T1056.001 Input Capture: Keylogging; T1056.004 Input Capture: Credential API Hooking; T1113 Screen Capture; T1115 Clipboard Data
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1102 Web Service
Credential Access
T1110 Brute Force; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
Affected products and versions in Remcos RAT Phishing Campaign Abusing Google Cloud Storage
- Microsoft — Windows (all supported SKUs)
Vulnerable versions: Windows 10 21H2+; Windows 11 22H2+; Windows Server 2019/2022/2025 - Microsoft — .NET Framework (RegSvcs.exe utility)
Vulnerable versions: .NET Framework 4.x (all versions) - Google — Google Cloud Storage (storage.googleapis.com)
Vulnerable versions: abused via anonymous-read public buckets - Breaking Security — Remcos (abused commercial RAT)
Vulnerable versions: Remcos v4.x and newer
Remediation for Remcos RAT Phishing Campaign Abusing Google Cloud Storage
Immediate actions
- Block or URL-filter *.storage.googleapis.com for executable (.exe, .dll), script (.js, .vbs, .ps1, .hta), and archive (.zip, .rar, .7z) MIME types at the Secure Email Gateway and web proxy
- Block the Remcos C2 IP 198.187.29.19 and associated CIDR 198.187.28.0/22 at the perimeter
- Hunt for HKCU\Software\Remcos-* registry keys across the fleet
- Hunt for RegSvcs.exe making outbound TCP connections or launching non-.NET child processes
- Hunt for wscript.exe -> powershell.exe parent/child chains originating from %TEMP% or %USERPROFILE%\Downloads
- Quarantine any files matching Bid-Packet-INV-Document.js, DYHVQ.ps1, or ZIFDG.tmp in %APPDATA%\WindowsUpdate\
Workarounds
- Disable Windows Script Host via HKLM\Software\Microsoft\Windows Script Host\Settings Enabled=0 on workstations where scripting is not required
- Restrict RegSvcs.exe execution via AppLocker / WDAC publisher rules that deny non-system invocation
- Deploy Attack Surface Reduction (ASR) rules in Audit mode first, then Block, for script and Office-child-process categories
Longer-term hardening
- Deploy Microsoft Defender ASR rules D3E037E1-3EB8-44C8-A917-57927947596D (Block JS/VBS launching downloaded executable) and 5BEB7EFE-FD9A-4556-801D-275E5FFC04CC (Block execution of potentially obfuscated scripts)
- Remove .js and .vbs default handler associations from Windows Script Host for end-user workstations
- Enable PowerShell ScriptBlock logging (Event ID 4104) and Module logging for detection of obfuscated downloaders
- Deploy an EDR product with process-hollowing and RWX memory allocation detections (Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Elastic Defend)
- Mandate DMARC reject policy and SPF hardfail for inbound mail to reduce pre-delivery exposure
- User awareness training focused on trusted-domain phishing (googleapis.com, onedrive.live.com, firebaseapp.com, github.io abuse)
Weaknesses (CWE) in Remcos RAT Phishing Campaign Abusing Google Cloud Storage
Timeline of Remcos RAT Phishing Campaign Abusing Google Cloud Storage
- Breaking Security (Germany) releases Remcos as a commercial Remote Control and Surveillance tool; quickly abused by cybercrime operators.
- ANY.RUN telemetry first observes malicious storage.googleapis.com/pa-bids/* payloads in public sandbox submissions.
- First ANY.RUN recorded execution showing ZIFDG.tmp loader process-hollowing RegSvcs.exe with Remcos RAT payload.
- Remcos C2 endpoint 198.187.29.19:2404 confirmed active by multiple sandbox detonations.
- ANY.RUN publishes blog post detailing the campaign's delivery chain, IOCs, and Google Cloud Storage bucket abuse.
- Cybersecurity News, GBHackers, and Cyberpress republish and expand analysis, raising industry awareness of the trusted-SaaS abuse pattern.
- ANY.RUN telemetry confirms operator rotated from pa-bids / com-bid to contract-bid-0 / in-bids / out-bid after Google abuse takedowns.
- Threadlinqs Intelligence publishes TL-2026-0409 with full kill-chain documentation, IOCs, MITRE mapping, and defender guidance.
- As of 2026-05-29, this remains a live concern: no CVE/patch applies, and Remcos RAT plus its trusted-SaaS + RegSvcs.exe process-hollowing TTPs are under heavy ongoing abuse (Jan-May 2026 campaigns). The specific April GCS buckets/C2 198.187.29.19 are ephemeral and likely rotated, but the unattributed operator persists with no takedown or arrest.
Sources cited for Remcos RAT Phishing Campaign Abusing Google Cloud Storage
- ANY.RUN: Google Cloud Phishing Drops Remcos RAT
- Cybersecurity News: Google Cloud Storage Abuse Delivers Remcos RAT via Phishing
- GBHackers: New Phishing Campaign Exploits Google Storage to Deliver Remcos RAT
- Cyberpress: Remcos RAT Delivered Through Google Cloud Storage in Email Evasion Campaign
- MITRE ATT&CK T1566.002 Spearphishing Link
- MITRE ATT&CK T1055.012 Process Hollowing
- LOLBAS Project: RegSvcs.exe
- Malpedia: Remcos RAT Family Profile
- Microsoft Defender ASR Rules Reference
- Google Cloud Abuse Reporting
Detection coverage for TL-2026-0409
As of 2026-04-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0409 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.