Nimbus RAT (BackupBOX) — Microsoft Teams Vishing + Quick Assist Delivery of a Self-Contained Java RAT Using Google Drive/Sheets for C2 (BlackSuit Affiliate) — Threadlinqs Intelligence
As of 2026-06-06, Nimbus RAT (BackupBOX) — Microsoft Teams Vishing + Quick Assist Delivery of a Self-Contained Java RAT Using Google Drive/Sheets for C2 (BlackSuit Affiliate) is a high-severity malware threat attributed to BlackSuit affiliate, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0691 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: BlackSuit affiliate · FINANCIAL
Nimbus RAT is a self-contained Java implant (internal name BackupBOX) that bundles its own OpenJDK 25 runtime and uses Google Drive service-account/OAuth2 channels plus a direct TLS socket for
Nimbus RAT is a Java-based remote access trojan distributed through a fully social-engineered, hands-on-keyboard intrusion chain that abuses trusted SaaS and OS tooling across the entire kill chain. eSentire's Threat Response Unit (TRU) reconstructed a representative April 6, 2026 intrusion against a legal-sector organization.
INTRUSION CHAIN: (1) Email bombing — the victim mailbox was flooded with ~282 legitimate transactional/subscription-confirmation emails (peak 26/min) from 116 unique sender domains over ~90 minutes (16:00-17:30 UTC), manufacturing urgency and a pretext for help. (2) Teams vishing — within ~45 minutes (~17:45 UTC) an external Microsoft Teams account on a throwaway *.onmicrosoft.com trial tenant, posing as internal IT helpdesk, contacted the user referencing the inbox flood and offered to help. (3) Remote access — the actor directed the user to launch Quick Assist via Windows Explorer, gaining an interactive remote session by 17:48 UTC. (4) Instruction delivery — the actor pasted a Pastebin URL (pastebin.com/G6jA0PLU, visited 17:53 UTC) into Teams chat containing a four-line human-readable checklist: download path, extraction directory, registry import, and Startup persistence step. (5) Payload staging — the archive InboxCorePro.zip was hosted on a compromised Microsoft 365 tenant's personal OneDrive (*-my.sharepoint.com), downloaded 17:54-17:56 UTC. (6) Execution & persistence — the user extracted to C:\ProgramData\InboxCorePro\, imported InboxCorePro.reg via regedit.exe (17:59:28 UTC) placing a launcher in the Startup folder; javaw.exe then executed InboxCorePro.jar at 17:59:32 UTC under parent explorer.exe. The actor returned via a second Quick Assist session at 18:04 UTC.
MALWARE: Nimbus RAT (internal name BackupBOX, OAuth app name BackupBOX, campaign UUID 1hc1his4gmto0q1) is self-contained — it ships its own OpenJDK 25.0.1 javaw.exe so no system Java is required. A %TEMP%\java_app.lock file enforces single-instance execution, and a license.txt kill-switch file prevents relaunch if removed. Java packages are name-obfuscated (BlackStatelessness, DomitianUndrapedEpigrammatize, EpitaphDunderhead, Goferindubitably, Splendrousstile, WorldlySiege, sententiousness, ExtricableSophisticated); entry point Goferindubitably.Audiometric, command handler Splendrousstile.SomewhatJerky, code execution DomitianUndrapedEpigrammatize.MutagenInchoateness.
COMMAND-AND-CONTROL: Three RSA-4096-encrypted channels. (a) Google Drive service account (class Keenplainspokenness) via ServiceAccountCredentials JSON key; (b) Google Drive OAuth2 user (class Intervention) via client_id+client_secret+refresh_token with rate-limit retry (7 attempts); (c) direct TLS socket (class phonemicsVandalism) with certificate validation disabled and RSA length-prefixed messages. Normal poll interval 45-75s, accelerated 4-8s wakeup poll. C2 files follow entry_{campaignUUID} (commands), exit_{campaignUUID} (responses), newconfig_* (config updates); large messages are chunked. All traffic uses a hardcoded 4096-bit RSA public key.
CAPABILITIES: Shell (cmd.exe /c, direct ProcessBuilder 'r' with 30s timeout, silent 'exec' to NUL); file ops (ls/dir, type, del/rm recursive, cd, tree max 5000, regex find max 5000, ZIP za/tz/z); registry full access (HKLM/HKCU/HKCR/HKU/HKCC query/add/delete); recon via JNA (GetNetworkParams/GetAdaptersInfo, sysinfo, domain/group membership); Robot screenshot to ZIP; and second-stage in-memory Java compile/execute (jc blocking, jcb backgrounded) accepting Base64 source where '/// https://' lines fetch dependency JARs to %TEMP%\libs\, compiled via javax.tools with no disk writes (MemoryClassLoader). Self-destruct ('self'): timeout /t 2 & RD /S /Q {jdkPath} then System.exit(0).
CREDENTIAL THEFT: 'lf' renders a fake Java Swing Windows Security dialog (DOMAIN\username pre-filled, 'Remember credentials' box) that fakes an 'incorrect' error on the first attempt and exfiltrates both password entries; 'cf' invokes the real CredU
Target sectors: legal, professional services, financial, technology
Target regions: North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1566, T1566, T1199, T1204, T1059, T1559, T1547, T1547