Remcos RAT is being delivered in a new phishing campaign that abuses Google Cloud Storage and trusted Google domains to evade detection, combining credential theft with a stealthy, multi‑stage malware chain.
ANY.RUN researchers recently analyzed a phishing operation that hosts malicious HTML pages directly on storage.googleapis.com, using Google Drive–style document lures to trick users.
Because the links point to legitimate Google Cloud Storage infrastructure, many secure email gateways and web filters allow the messages through, as DMARC, SPF, and DKIM checks all appear valid, and the domain reputation looks clean.
The phishing pages closely imitate the Google Drive viewer and Workspace login, including Google branding, file‑type icons, and prompts to “sign in to view document,” which lowers suspicion for users who routinely work with cloud documents. Google Cloud Storage infrastructureGoogle Cloud Storage infrastructure

Impact and Defensive Focus for Security Teams
This campaign shows how attackers weaponize trust at multiple levels: Google Cloud Storage provides a reputable hosting domain, the email authentication stack validates successfully, and RegSvcs.exe appears as a benign Microsoft binary in logs.
Traditional filters that rely on domain reputation, static signatures, or simple file hashes are likely to miss this activity, especially in environments where googleapis.com and signed Windows binaries are routinely allowed.

As a result, the mean time to detect can stretch significantly, giving adversaries hours or even days to escalate privileges, pivot inside the network, and compromise additional systems.
For enterprises, the risk is amplified when phishing targets executives, finance, and procurement roles, where access to financial workflows, sensitive documents, and third‑party relationships is concentrated.

A single compromised endpoint can lead to direct financial fraud, data‑protection violations, ransomware incidents, and cascading supply‑chain exposure if vendor environments are involved.
Security teams need to prioritize behavioral detections that monitor script spawning chains (JS → VBS → PowerShell), anomalous RegSvcs.exe activity, in‑memory .NET assembly loading, and unusual outbound connections tied to sandbox‑observed Remcos infrastructure.
Behavior‑centric sandboxing and high‑fidelity threat intelligence are emerging as critical controls against these trusted‑infrastructure attacks.
ANY.RUN’s interactive sandbox allows analysts to drive suspicious sessions manually, wait out time‑based evasions, and see the full kill chain from the initial phishing link through to Remcos C2 callbacks, which can then be translated into rules mapped to MITRE ATT&CK, Sigma detections for SIEM and EDR, and actionable indicators.
Its Threat Intelligence Lookup and feeds extend this visibility across environments, helping SOC teams pivot from a single observed indicator to the broader campaign, then push unique, behavior‑rich indicators into their detection stack for proactive hunting and automated blocking.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.