GoogleDrive RAT - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:16:50 UTC Home > List all groups > List all tools > List all groups using tool GoogleDrive RAT Tool: GoogleDrive RAT Names GoogleDrive RAT Category Malware Type Backdoor Description (Nyotron) Some of the compromised servers contained an innovative Google Drive-based RAT under the name Service.exe. The attacker moved Service.exe to C:\Windows\system32 along with a large set of files. These files included DLLs related to the Google API used for communication and more. Information Malpedia Last change to this tool card: 23 April 2020 Download this tool card in JSON format All groups using tool GoogleDrive RAT Changed Name Country Observed APT groups   OilRig, APT 34, Helix Kitten, Chrysene 2014-Sep 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=789aa471-f872-4252-b492-c68d2d8bf8ff https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=789aa471-f872-4252-b492-c68d2d8bf8ff Page 1 of 1