Threats Tagged 'google drive'
View all threats tagged with 'google drive'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'google drive'
Click on any threat for detailed analysis and mitigation recommendations
RedKitten is a newly identified campaign targeting Iranian interests, first observed in January 2026. The malware uses GitHub and Google Drive for configuration and payload retrieval, and Telegram for command and control. It appears to exploit the Dey 1404 Protests in Iran, targeting organizations documenting human rights abuses. The threat actor rapidly built this campaign using AI tools, as evidenced by traces of LLM-assisted development. While attribution is not definitive, the activity aligns with Iranian state-sponsored attackers. The malware, dubbed SloppyMIO, can fetch modules, execute commands, collect files, and deploy additional malware with persistence. Join the discussion | AlienVault OTX General | 01/29/2026, 21:45:57 UTC Added: 01/30/2026, 08:12:47 UTC |
Pakistan-linked APT36 (Transparent Tribe) launched a new cyber-espionage campaign targeting Indian government and defense entities. Active in August 2025, the group used phishing ZIP files containing malicious Linux “.desktop” shortcuts that downloaded payloads from Google Drive. Join the discussion | AlienVault OTX General | 08/21/2025, 21:05:42 UTC Added: 08/21/2025, 21:17:47 UTC |
The report analyzes Advanced Persistent Threat (APT) attacks in South Korea during July 2025. Spear phishing was the primary attack method, with LNK files being the most common vector. Two types of LNK-based attacks were identified: Type A, which uses compressed CAB files containing malicious scripts, and Type B, which executes RAT malware like XenoRAT and RoKRAT. The attacks targeted various sectors, including finance and blockchain, using sophisticated techniques such as email spoofing and exploiting product vulnerabilities. The report provides detailed information on file names, MD5 hashes, URLs, and IP addresses associated with these attacks, highlighting the ongoing threat to South Korean organizations. Join the discussion | AlienVault OTX General | 08/19/2025, 16:07:37 UTC Added: 08/19/2025, 21:17:47 UTC |
A cluster of suspicious activity, tracked as CL-STA-1020, has been targeting governmental entities in Southeast Asia since late 2024. The threat actors have developed a new Windows backdoor called HazyBeacon, which uses AWS Lambda URLs for command and control communication. This technique leverages legitimate cloud functionality to create a covert, scalable, and hard-to-detect communication channel. The attackers' primary goal appears to be covert intelligence gathering, focusing on sensitive government data related to trade disputes. They also use Google Drive and Dropbox for data exfiltration, blending with normal network traffic. The attack involves DLL sideloading, persistence through a Windows service, and various payloads for file collection and exfiltration. Join the discussion | AlienVault OTX General | 07/14/2025, 14:05:53 UTC Added: 07/15/2025, 09:31:04 UTC |
Showing 1 to 4 of 4 results