Threat reportPhishingTL-2026-0409

Remcos RAT Phishing Campaign Abusing Google Cloud Storage (storage.googleapis.com) with RegSvcs.exe Process Hollowing

highMONITORING

Remcos RAT Phishing Campaign Abusing Google Cloud Storage (TL-2026-0409), also tracked as Bid-Lure Remcos Campaign, is a high-severity phishing campaign, first published 2026-04-22. It has no confirmed attribution, affects Microsoft Windows (all supported SKUs), maps to 21 MITRE ATT&CK techniques (T1027, T1036.004, T1041), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-0409

Threat ID
TL-2026-0409
Also known as
Bid-Lure Remcos Campaign, Google Cloud Storage Remcos Phish, GCS Drive Phish
Severity
HIGH
Status
MONITORING
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
financial, government, construction, manufacturing, legal, professional-services, energy, healthcare
Target regions
North America, Europe, Latin America, Asia-Pacific
Detection rules
9
Indicators of compromise
26

Malware and tooling in Remcos RAT Phishing Campaign Abusing Google Cloud Storage

Malware and tooling: Remcos, Remcos RAT v4.x, RegSvcs.exe, Remcos RAT C2 (TCP 2404), wscript.exe

How Remcos RAT Phishing Campaign Abusing Google Cloud Storage works

ANY.RUN, Cybersecurity News, and GBHackers have disclosed an active phishing campaign abusing storage.googleapis.com buckets (pa-bids, com-bid, contract-bid-0, in-bids, out-bid) to host fake Google Drive login pages and deliver Remcos RAT. The multi-stage chain uses a JScript bait (Bid-Packet-INV-Document.js), PowerShell downloader (DYHVQ.ps1), and a binary loader (ZIFDG.tmp) that process-hollows the signed Microsoft .NET utility RegSvcs.exe to run Remcos in memory. Abuse of trusted Google infrastructure bypasses DMARC/SPF/DKIM checks and URL-reputation email gateways; C2 beacons to 198.187.29.19.

Overview -------- In April 2026, ANY.RUN, Cybersecurity News, GBHackers, and Cyberpress published analyses of an ongoing Remcos RAT phishing campaign that abuses Google Cloud Storage (storage.googleapis.com) to host intermediate payloads and fake Google Drive sign-in pages. The campaign is not a new vulnerability; it is a weaponization of trusted SaaS hosting for payload delivery and credential theft, coupled with a signed-binary-proxy execution chain that terminates in process hollowing of RegSvcs.exe (the Microsoft .NET Services Installation utility).

Delivery and Lure ----------------- Victims receive business-themed lures (invoices, bid packets, contract attachments) that link to storage.googleapis.com URLs such as storage.googleapis.com/com-bid/GoogleDrive.html and storage.googleapis.com/pa-bids/*. Because storage.googleapis.com is a Google-owned domain with a valid TLS certificate and high reputation score, URL-reputation email security gateways and browser SmartScreen-style reputation engines do not flag the links. The HTML page renders a pixel-accurate clone of the Google Drive login experience. Submitted credentials are exfiltrated to an attacker-controlled endpoint, after which the page serves a JScript file named Bid-Packet-INV-Document.js (archived inside a ZIP with a document-lookalike icon).

Stage 1 - JScript Dropper ------------------------- When the victim double-clicks the .js file, wscript.exe is invoked. The JScript is heavily obfuscated (string concatenation, base64-encoded blobs, character-code reconstruction) and resolves to a PowerShell command executed via powershell.exe -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden. This stage maps to T1059.005 (Visual Basic / JScript) and T1027 (Obfuscated Files or Information).

Stage 2 - PowerShell Downloader ------------------------------- The PowerShell stage (observed file DYHVQ.ps1) downloads an encrypted binary blob from another storage.googleapis.com bucket (contract-bid-0, in-bids, out-bid rotated), writes it to %APPDATA%\WindowsUpdate\ZIFDG.tmp, decodes it with a simple XOR/AES routine (T1140 Deobfuscate / Decode Files), and executes it. Persistence is installed via HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run (T1547.001 Registry Run Keys).

Stage 3 - RegSvcs.exe Process Hollowing --------------------------------------- The ZIFDG.tmp loader spawns a suspended instance of the signed Microsoft binary RegSvcs.exe (%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe), unmaps its image, writes the Remcos RAT PE into the cleared memory region using NtUnmapViewOfSection + WriteProcessMemory + SetThreadContext + ResumeThread, and resumes execution. This matches T1055.012 (Process Hollowing) and T1218 (Signed Binary Proxy Execution) via the trusted .NET utility. Because RegSvcs.exe is Microsoft-signed and whitelisted by most EDR reputation engines, behavioural signatures rather than reputation must catch the execution.

Remcos RAT Post-Exploitation ---------------------------- Remcos is a commercial Remote Control and Surveillance tool sold by Germany-based Breaking Security, widely abused by cybercrime actors since 2016. Capabilities observed in this campaign: keylogging (T1056.001), screenshot capture, credential theft from browsers (T1555.003), clipboard monitoring (T1056.004), and file exfiltration over the C2 channel (T1041 Exfiltration Over C2 Channel). The Remcos configuration beacons to 198.187.29.19 on TCP 2404 (the default Remcos port range). A Remcos identifier registry key is dropped at HKEY_CURRENT_USER\Software\Remcos-{random 8-char ID}.

Infrastructure Abuse -------------------- Five Google Cloud Storage buckets have been identified as weaponized: pa-bids, com-bid, contract-bid-0, in-bids, out-bid. Bucket names mimic procurement / bidding vocabulary to blend with the business lure. Google's abuse response typically removes reported buckets within 24-72 hours, but the operator rotates to freshly provisioned buckets using the same naming pattern. This matches T1583.006 (Acquire Infrastructure: Web Services) and T1102 (Web Service) as alternate TTP mappings.

Why This Campaign Matters ------------------------- (1) Email security bypass: storage.googleapis.com inherits Google's TLS cert, DMARC/SPF/DKIM alignment, and reputation; most Secure Email Gateways allowlist *.googleapis.com. (2) Signed-binary-proxy execution: RegSvcs.exe is a LOLBAS entry already; pairing it with process hollowing defeats application-allowlisting solutions that trust Microsoft-signed binaries by hash or publisher. (3) Remcos RAT is under active commodity-malware use by multiple distinct operators (FIN7 affiliates, UNC-designated clusters, and independent criminal crews), so attribution is deliberately left as Unknown commodity-malware operators.

Defender Priorities ------------------- - Block or alert on *.storage.googleapis.com URLs carrying executable, archive, or script MIME types at the proxy / SEG layer. - Hunt for RegSvcs.exe child / network activity (it should virtually never make outbound TCP connections or be a parent of unusual processes in a typical enterprise). - Alert on HKCU\Software\Remcos-* registry key creation. - Deploy ASR rule 'Block JavaScript or VBScript from launching downloaded executable content' (GUID D3E037E1-3EB8-44C8-A917-57927947596D).

MITRE ATT&CK techniques used in TL-2026-0409

Defense Evasion

T1027 Obfuscated Files or Information; T1036.004 Masquerading: Masquerade Task or Service; T1055.012 Process Injection: Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

Exfiltration

T1041 Exfiltration Over C2 Channel

Collection

T1056.001 Input Capture: Keylogging; T1056.004 Input Capture: Credential API Hooking; T1113 Screen Capture; T1115 Clipboard Data

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1102 Web Service

Credential Access

T1110 Brute Force; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.006 Acquire Infrastructure: Web Services

Affected products and versions in Remcos RAT Phishing Campaign Abusing Google Cloud Storage

  • Microsoft — Windows (all supported SKUs)
    Vulnerable versions: Windows 10 21H2+; Windows 11 22H2+; Windows Server 2019/2022/2025
  • Microsoft — .NET Framework (RegSvcs.exe utility)
    Vulnerable versions: .NET Framework 4.x (all versions)
  • Google — Google Cloud Storage (storage.googleapis.com)
    Vulnerable versions: abused via anonymous-read public buckets
  • Breaking Security — Remcos (abused commercial RAT)
    Vulnerable versions: Remcos v4.x and newer

Remediation for Remcos RAT Phishing Campaign Abusing Google Cloud Storage

Immediate actions

  • Block or URL-filter *.storage.googleapis.com for executable (.exe, .dll), script (.js, .vbs, .ps1, .hta), and archive (.zip, .rar, .7z) MIME types at the Secure Email Gateway and web proxy
  • Block the Remcos C2 IP 198.187.29.19 and associated CIDR 198.187.28.0/22 at the perimeter
  • Hunt for HKCU\Software\Remcos-* registry keys across the fleet
  • Hunt for RegSvcs.exe making outbound TCP connections or launching non-.NET child processes
  • Hunt for wscript.exe -> powershell.exe parent/child chains originating from %TEMP% or %USERPROFILE%\Downloads
  • Quarantine any files matching Bid-Packet-INV-Document.js, DYHVQ.ps1, or ZIFDG.tmp in %APPDATA%\WindowsUpdate\

Workarounds

  • Disable Windows Script Host via HKLM\Software\Microsoft\Windows Script Host\Settings Enabled=0 on workstations where scripting is not required
  • Restrict RegSvcs.exe execution via AppLocker / WDAC publisher rules that deny non-system invocation
  • Deploy Attack Surface Reduction (ASR) rules in Audit mode first, then Block, for script and Office-child-process categories

Longer-term hardening

  • Deploy Microsoft Defender ASR rules D3E037E1-3EB8-44C8-A917-57927947596D (Block JS/VBS launching downloaded executable) and 5BEB7EFE-FD9A-4556-801D-275E5FFC04CC (Block execution of potentially obfuscated scripts)
  • Remove .js and .vbs default handler associations from Windows Script Host for end-user workstations
  • Enable PowerShell ScriptBlock logging (Event ID 4104) and Module logging for detection of obfuscated downloaders
  • Deploy an EDR product with process-hollowing and RWX memory allocation detections (Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Elastic Defend)
  • Mandate DMARC reject policy and SPF hardfail for inbound mail to reduce pre-delivery exposure
  • User awareness training focused on trusted-domain phishing (googleapis.com, onedrive.live.com, firebaseapp.com, github.io abuse)

Weaknesses (CWE) in Remcos RAT Phishing Campaign Abusing Google Cloud Storage

CWE-20, CWE-601, CWE-829

Timeline of Remcos RAT Phishing Campaign Abusing Google Cloud Storage

  • Breaking Security (Germany) releases Remcos as a commercial Remote Control and Surveillance tool; quickly abused by cybercrime operators.
  • ANY.RUN telemetry first observes malicious storage.googleapis.com/pa-bids/* payloads in public sandbox submissions.
  • First ANY.RUN recorded execution showing ZIFDG.tmp loader process-hollowing RegSvcs.exe with Remcos RAT payload.
  • Remcos C2 endpoint 198.187.29.19:2404 confirmed active by multiple sandbox detonations.
  • ANY.RUN publishes blog post detailing the campaign's delivery chain, IOCs, and Google Cloud Storage bucket abuse.
  • Cybersecurity News, GBHackers, and Cyberpress republish and expand analysis, raising industry awareness of the trusted-SaaS abuse pattern.
  • ANY.RUN telemetry confirms operator rotated from pa-bids / com-bid to contract-bid-0 / in-bids / out-bid after Google abuse takedowns.
  • Threadlinqs Intelligence publishes TL-2026-0409 with full kill-chain documentation, IOCs, MITRE mapping, and defender guidance.
  • As of 2026-05-29, this remains a live concern: no CVE/patch applies, and Remcos RAT plus its trusted-SaaS + RegSvcs.exe process-hollowing TTPs are under heavy ongoing abuse (Jan-May 2026 campaigns). The specific April GCS buckets/C2 198.187.29.19 are ephemeral and likely rotated, but the unattributed operator persists with no takedown or arrest.

Sources cited for Remcos RAT Phishing Campaign Abusing Google Cloud Storage

Detection coverage for TL-2026-0409

As of 2026-04-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0409 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats