# Remcos RAT Phishing Campaign Abusing Google Cloud Storage (storage.googleapis.com) with RegSvcs.exe Process Hollowing

> ANY.RUN, Cybersecurity News, and GBHackers have disclosed an active phishing campaign abusing storage.googleapis.com buckets (pa-bids, com-bid, contract-bid-0, in-bids, out-bid) to host fake Google Drive login pages and deliver Remcos RAT. The multi-stage chain uses a JScript bait (Bid-Packet-INV-Document.js), PowerShell downloader (DYHVQ.ps1), and a binary loader (ZIFDG.tmp) that process-hollows the signed Microsoft .NET utility RegSvcs.exe to run Remcos in memory. Abuse of trusted Google infrastructure bypasses DMARC/SPF/DKIM checks and URL-reputation email gateways; C2 beacons to 198.187.29.19.

- **Published:** 2026-04-22T12:00:00Z
- **Last reviewed:** 2026-04-22T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0409
- **ID:** TL-2026-0409
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Overview
--------
In April 2026, ANY.RUN, Cybersecurity News, GBHackers, and Cyberpress published analyses of an ongoing Remcos RAT phishing campaign that abuses Google Cloud Storage (storage.googleapis.com) to host intermediate payloads and fake Google Drive sign-in pages. The campaign is not a new vulnerability; it is a weaponization of trusted SaaS hosting for payload delivery and credential theft, coupled with a signed-binary-proxy execution chain that terminates in process hollowing of RegSvcs.exe (the Microsoft .NET Services Installation utility).

Delivery and Lure
-----------------
Victims receive business-themed lures (invoices, bid packets, contract attachments) that link to storage.googleapis.com URLs such as storage.googleapis.com/com-bid/GoogleDrive.html and storage.googleapis.com/pa-bids/*. Because storage.googleapis.com is a Google-owned domain with a valid TLS certificate and high reputation score, URL-reputation email security gateways and browser SmartScreen-style reputation engines do not flag the links. The HTML page renders a pixel-accurate clone of the Google Drive login experience. Submitted credentials are exfiltrated to an attacker-controlled endpoint, after which the page serves a JScript file named Bid-Packet-INV-Document.js (archived inside a ZIP with a document-lookalike icon).

Stage 1 - JScript Dropper
-------------------------
When the victim double-clicks the .js file, wscript.exe is invoked. The JScript is heavily obfuscated (string concatenation, base64-encoded blobs, character-code reconstruction) and resolves to a PowerShell command executed via powershell.exe -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden. This stage maps to T1059.005 (Visual Basic / JScript) and T1027 (Obfuscated Files or Information).

Stage 2 - PowerShell Downloader
-------------------------------
The PowerShell stage (observed file DYHVQ.ps1) downloads an encrypted binary blob from another storage.googleapis.com bucket (contract-bid-0, in-bids, out-bid rotated), writes it to %APPDATA%\WindowsUpdate\ZIFDG.tmp, decodes it with a simple XOR/AES routine (T1140 Deobfuscate / Decode Files), and executes it. Persistence is installed via HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run (T1547.001 Registry Run Keys).

Stage 3 - RegSvcs.exe Process Hollowing
---------------------------------------
The ZIFDG.tmp loader spawns a suspended instance of the signed Microsoft binary RegSvcs.exe (%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe), unmaps its image, writes the Remcos RAT PE into the cleared memory region using NtUnmapViewOfSection + WriteProcessMemory + SetThreadContext + ResumeThread, and resumes execution. This matches T1055.012 (Process Hollowing) and T1218 (Signed Binary Proxy Execution) via the trusted .NET utility. Because RegSvcs.exe is Microsoft-signed and whitelisted by most EDR reputation engines, behavioural signatures rather than reputation must catch the execution.

Remcos RAT Post-Exploitation
----------------------------
Remcos is a commercial Remote Control and Surveillance tool sold by Germany-based Breaking Security, widely abused by cybercrime actors since 2016. Capabilities observed in this campaign: keylogging (T1056.001), screenshot capture, credential theft from browsers (T1555.003), clipboard monitoring (T1056.004), and file exfiltration over the C2 channel (T1041 Exfiltration Over C2 Channel). The Remcos configuration beacons to 198.187.29.19 on TCP 2404 (the default Remcos port range). A Remcos identifier registry key is dropped at HKEY_CURRENT_USER\Software\Remcos-{random 8-char ID}.

Infrastructure Abuse
--------------------
Five Google Cloud Storage buckets have been identified as weaponized: pa-bids, com-bid, contract-bid-0, in-bids, out-bid. Bucket names mimic procurement / bidding vocabulary to blend with the business lure. Google's abuse response typically removes reported buckets within 24-72 hours, but the operator rotates to freshly provisioned buckets using the same naming pattern. This matches T1583.006 (Acquire Infrastructure: Web Services) and T1102 (Web Service) as alternate TTP mappings.

Why This Campaign Matters
-------------------------
(1) Email security bypass: storage.googleapis.com inherits Google's TLS cert, DMARC/SPF/DKIM alignment, and reputation; most Secure Email Gateways allowlist *.googleapis.com. (2) Signed-binary-proxy execution: RegSvcs.exe is a LOLBAS entry already; pairing it with process hollowing defeats application-allowlisting solutions that trust Microsoft-signed binaries by hash or publisher. (3) Remcos RAT is under active commodity-malware use by multiple distinct operators (FIN7 affiliates, UNC-designated clusters, and independent criminal crews), so attribution is deliberately left as Unknown commodity-malware operators.

Defender Priorities
-------------------
- Block or alert on *.storage.googleapis.com URLs carrying executable, archive, or script MIME types at the proxy / SEG layer.
- Hunt for RegSvcs.exe child / network activity (it should virtually never make outbound TCP connections or be a parent of unusual processes in a typical enterprise).
- Alert on HKCU\Software\Remcos-* registry key creation.
- Deploy ASR rule 'Block JavaScript or VBScript from launching downloaded executable content' (GUID D3E037E1-3EB8-44C8-A917-57927947596D).

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1583.006 Acquire Infrastructure: Web Services
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1204.002 User Execution: Malicious File
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1055.012 Process Injection: Process Hollowing
- T1218 System Binary Proxy Execution
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036.004 Masquerading: Masquerade Task or Service
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1110 Brute Force
- T1056.001 Input Capture: Keylogging
- T1056.004 Input Capture: Credential API Hooking
- T1115 Clipboard Data
- T1113 Screen Capture
- T1071.001 Application Layer Protocol: Web Protocols
- T1095 Non-Application Layer Protocol
- T1102 Web Service
- T1041 Exfiltration Over C2 Channel

## Sources

- [ANY.RUN: Google Cloud Phishing Drops Remcos RAT](https://any.run/cybersecurity-blog/phishing-google-drive-remcos/)
- [Cybersecurity News: Google Cloud Storage Abuse Delivers Remcos RAT via Phishing](https://cybersecuritynews.com/google-cloud-storage-remcos-rat-phishing/)
- [GBHackers: New Phishing Campaign Exploits Google Storage to Deliver Remcos RAT](https://gbhackers.com/phishing-campaign-exploits-google/)
- [Cyberpress: Remcos RAT Delivered Through Google Cloud Storage in Email Evasion Campaign](https://cyberpress.org/google-cloud-delivers-remcos/)
- [MITRE ATT&CK T1566.002 Spearphishing Link](https://attack.mitre.org/techniques/T1566/002/)
- [MITRE ATT&CK T1055.012 Process Hollowing](https://attack.mitre.org/techniques/T1055/012/)
- [LOLBAS Project: RegSvcs.exe](https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/)
- [Malpedia: Remcos RAT Family Profile](https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos)
- [Microsoft Defender ASR Rules Reference](https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference)
- [Google Cloud Abuse Reporting](https://support.google.com/code/contact/cloud_platform_report)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0409
