SYMBOLCOMMON_NAMEaka. SYNONYMS
win.gdrive (Back to overview)

Gdrive

aka: DoomDrive, GoogleDriveSucks

Actor(s): APT 29, APT29


According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim information uploaded and payloads delivered.

References
2023-03-27 ⋅ Google ⋅ Google Cybersecurity Action Team
Threat Horizons: April 2023 Threat Horizons Report
Gdrive APT41
2022-07-19 ⋅ Palo Alto Networks Unit 42 ⋅ Mike Harbison, Peter Renals
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
Cobalt Strike EnvyScout Gdrive
2022-07-19 ⋅ R136a1 ⋅ Dominik Reichel
A look into APT29's new early-stage Google Drive downloader
BEATDROP BOOMBOX Gdrive Unidentified 098 (APT29 Slack Downloader)

There is no Yara-Signature yet.