216.73.216.6

NANOREMOTE, cousin of FINALDRAFT

· Published 10/12/2025 18:35 · Modified 21/12/2025 18:58

Export JSON

Essential information

Published
10/12/2025 18:35
Modified
21/12/2025 18:58
Tags
2025-12-10 command execution custom pe loader file exfiltration finaldraft google drive api nanoremote task management windows backdoor wmloader
Related entities
5 observables, 5 techniques (mitre), 3 malware, 1 others

Description

A newly discovered called shares similarities with previously known malware . 's key feature is using the for data exfiltration and payload staging, making detection challenging. The malware includes a system for file transfers and incorporates functionality from open-source projects. It communicates with a hardcoded IP address over HTTP, using encrypted and compressed JSON data. has 22 command handlers enabling various capabilities such as system reconnaissance, file operations, and . The malware's similarity to suggests a shared codebase and development environment between the two threats.

External references