Cybercriminals Exploit OneDrive and Google Drive to Conceal Harmful Activity

Adversaries, including state-sponsored groups, are increasingly exploiting legitimate cloud platforms to conduct espionage, capitalizing on their discreet and economical nature. Platforms like Microsoft OneDrive and Google Drive are utilized to avoid detection by posing as reliable entities, which facilitates hidden data extraction and the development of malicious tools.

In November 2023, a novel Go-based backdoor known as GoGra was uncovered, targeting a South Asian media organization. GoGra utilizes the Microsoft Graph API for command and control (C2), accessing encrypted email instructions from a designated Outlook account, decrypting these commands with AES-256 CBC encryption, and executing them through cmd.exe.

Covering Their Tracks with Cloud Services

The backdoor GoGra, attributed to the nation-state group Harvester, exhibits functional similarities to the group’s .NET-based Graphon tool but differs in its programming language, encryption method, command set, and C2 setup.

Similarly, the Firefly espionage group utilized a custom Python wrapper for a public Google Drive client to exfiltrate sensitive data from a Southeast Asian military organization. The attackers focused on .jpg files within the System32 directory, employing a hardcoded refresh token to upload encrypted RAR files containing documents, meeting notes, call transcripts, architectural plans, email folders, and financial records to a Google Drive account.

In April 2024, a new backdoor, Trojan.Grager, targeted Asian organizations using the Microsoft Graph API for C&C communication. The attack involved a typosquatted URL posing as a legitimate 7-Zip installer (hxxp://7-zip.tw/a/7z2301-x64[.]msi). This MSI file installed genuine 7-Zip software alongside a malicious DLL (epdevmgr.dll), the Tonerjam malware, and the encrypted Grager backdoor (data.dat).

Mandiant identified Tonerjam as a launcher malware that activates the Grager backdoor, which is suspected to be associated with the China-linked espionage group UNC5330. This backdoor is capable of extracting system information, managing files, and executing commands, specifically targeting OneDrive credentials. UNC5330 has previously exploited Ivanti Connect Secure VPN vulnerabilities to compromise devices, underscoring their active threat presence.

Symantec has identified a new, under-development backdoor named MoonTag, which utilizes code from a public Google Group. MoonTag communicates via the Graph API and bears similarities to the 9002 RAT, though direct connections to Sabre Panda remain unverified. Strong indications suggest a Chinese-speaking threat actor based on code language and infrastructure.

OneDriveTools, a recent backdoor, targets IT service providers by using the Microsoft Graph API to download and execute payloads from OneDrive. It creates a unique folder for each victim, tracks infection status, and maintains communication through heartbeat files and command execution within this folder.

Attackers also employ Whipweave, a tunneling tool based on Free Connect, to interface with an Orbweaver network. This trend of using cloud-based command and control infrastructure reflects a broader pattern among threat actors.

To enhance security, best practices include blocking unused cloud services, monitoring network traffic for irregularities, potentially implementing application whitelisting, restricting cloud service access for non-browser processes, identifying critical assets for data exfiltration monitoring, and enabling host-based and cloud audit logging.

Indicators of Compromise (IOC)

  • Trojan.Gogra
  • d728cdcf62b497362a1ba9dbaac5e442cebe86145734410212d323a6c2959f0f
  • f1ccd604fcdc0034d94e575b3709cd124e13389bbee55c59cbbf7d4f3476e214
  • Trojan.Grager
  • 9f61ed14660d8f85d606605d1c4c23849bd7a05afd02444c3b33e3af591cfdc9
  • ab6a684146cec59ec3a906d9e018b318fb6452586e8ec8b4e37160bcb4adc985
  • 97551bd3ff8357831dc2b6d9e152c8968d9ce1cd0090b9683c38ea52c2457824
  • Trojan.Ondritols
  • f69fb19604362c5e945d8671ce1f63bb1b819256f51568daff6fed6b5cc2f274
  • 582b21409ee32ffca853064598c5f72309247ad58640e96287bb806af3e7bede
  • 79e56dc69ca59b99f7ebf90a863f5351570e3709ead07fe250f31349d43391e6
  • 4057534799993a63f41502ec98181db0898d1d82df0d7902424a1899f8f7f9d2
  • Trojan.Moontag
  • a76507b51d84708c02ca2bd5a5775c47096bc740c9f7989afd6f34825edfcba6
  • 527fada7052b955ffa91df3b376cc58d387b39f2f44ebdcb54bc134e112a1c14
  • fd9fc13dbd39f920c52fbc917d6c9ce0a28e0d049812189f1bb887486caedbeb
  • Whipweave
  • 30093c2502fed7b2b74597d06b91f57772f2ae50ac420bcaa627038af33a6982
  • Download URLs
  • hxxp://7-zip.tw/a/7z2301-x64[.]msi
  • hxxp://7-zip.tw/a/7z2301[.]msi
  • Typosquatted Domain
  • 7-zip[.]tw
  • C&C IP Addresses
  • 103.255.178[.]200 (MoonTag)
  • 157.245.159[.]135 (Whipweave)
  • 89.42.178[.]13 (Whipweave)
  • 30sof.onedumb[.]com (Whipweave)

More Articles & Posts