Nimbus RAT
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors used Microsoft Teams voice phishing (vishing) to deceive the victim into granting remote access via Quick Assist, then deployed a Java-based remote access trojan (RAT). TRU tracks this malware as Nimbus RAT.
Techniques & procedures
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Reconnaissance
1 techniqueThe malicious operators combine email harassment with voice phishing tactics to breach network perimeters.
Initial Access
2 techniquesPosing as internal support staff, the attacker convinced the user to launch Quick Assist | Microsoft Teams is used for initial access
attackers used Microsoft Teams voice phishing to trick a user into granting remote access via Windows Quick Assist
Execution
3 techniquesQuick Assist Launch and Initial Recon using cmd
...this multi-layered assault tricks corporate employees into downloading an advanced Java-based backdoor threat.
The downloaded archive contained a malicious Java archive, bundled with an OpenJDK runtime, allowing execution on any Windows system
Persistence
2 techniquesIt supports arbitrary command execution, file system manipulation, registry access
Privilege Escalation
1 techniqueStealth
2 techniquesDefense Impairment
1 techniqueCredential Access
2 techniquesNimbus RAT can display either a Java Swing imitation of the Windows Security credential prompt or invoke the real Windows CredUIPromptForCredentialsW API directly via JNA ... Both approaches are designed to capture two password entries
it includes dual credential-harvesting mechanisms: a fake Windows Security prompt and direct API invocation via CredUIPromptForCredentialsW
Discovery
3 techniquesReconnaissance ipconfig equiv. Full network adapter info via GetNetworkParams + GetAdaptersInfo (JNA)
Quick Assist Launch and Initial Recon using cmd
It supports arbitrary command execution, file system manipulation
Collection
3 techniquesNimbus RAT can display either a Java Swing imitation of the Windows Security credential prompt or invoke the real Windows CredUIPromptForCredentialsW API directly via JNA ... Both approaches are designed to capture two password entries
It supports arbitrary command execution, file system manipulation, registry access, screenshot capture
File system za / tz / z ZIP directory, ZIP single file inline, extract ZIP (with optional password)
Command and Control
6 techniquesthe malware communicates with legitimate Google APIs, making network-level detection extremely difficult | Nimbus RAT is a modular and highly capable implant... A defining feature of Nimbus RAT is its use of Google Drive and Google Sheets as C2 channels.
All command delivery and data exfiltration travels over legitimate Google API endpoints.
Commands are fetched from attacker-controlled Google Drive files, and exfiltrated data is uploaded in the same way.
The final payload was retrieved from a compromised Microsoft 365 tenant hosted on SharePoint
the attacker convinced the user to launch Quick Assist and follow step-by-step instructions
All C2 traffic is RSA-encrypted using a hardcoded 4096-bit public key embedded in the JAR.
Exfiltration
2 techniquesexfiltrated data is uploaded in the same way
The tool, which TRU identifies as InboxSetupPro ... uses OneDrive rather than Google Drive for exfiltration.
IOCs tracked for this family
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Java-based modular remote access trojan delivered via Quick Assist and a SharePoint-hosted archive. It establishes persistence, uses encrypted communications, abuses Google Drive and Google Sheets as command-and-control channels, supports arbitrary command execution, file system and registry access, screenshot capture, in-memory second-stage payload execution, and credential harvesting via fake Windows Security prompts and CredUIPromptForCredentialsW.
A Java-based remote access backdoor used after Microsoft Teams vishing attacks. It establishes persistence on endpoints and uses Google Drive and Google Sheets for command-and-control to blend malicious traffic with benign cloud activity.
Java-based remote access trojan used after Teams vishing and Quick Assist access. It bundles its own OpenJDK runtime, uses Google Drive and Google Sheets/Google APIs for command-and-control, supports shell execution, file operations, registry access, screenshots, credential theft via fake or native Windows prompts, and in-memory second-stage Java code execution. It does not autonomously install persistence; operators stage persistence separately.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.