For decades, the rule in IT security has been simple: "Block traffic to suspicious websites in Russia or China." But what do you do when the attack comes from a source you use every day at the office? In 2026, the NANOREMOTE threat changed the game.
At Altanet Craiova, we’ve noticed an increase in these sophisticated attacks that use legitimate infrastructure (Google, Microsoft, Dropbox) to slip past the firewall unnoticed. It’s like a thief walking out of a bank dressed in a police uniform.
How does NANOREMOTE work?
Most viruses try to communicate with the hacker’s server (“Command & Control”) to receive commands. Good antivirus software detects this connection and blocks it.
NANOREMOTE is different. It doesn’t connect to a suspicious server, but to a Google Drive, OneDrive, or Dropbox account created by hackers. Since your company allows employees to use these services, the traffic looks perfectly legitimate.
- Step 1: Infects the computer (via email or download).
- Step 2: Checks a text file in a public Google Drive account to receive commands (e.g., "Steal passwords from Chrome").
- Step 3: Upload the stolen data to the same Google Drive account as encrypted files.
To your firewall, it all looks like an employee doing their job and saving documents to the cloud.
Why is this so dangerous for businesses?
As a RAT (Remote Access Trojan), NANOREMOTE provides total control over the infected computer. The hacker can:
- See everything you type (keylogging).
- Take screenshots.
- Activate the webcam and microphone.
- Use your computer to attack other customers.
How do we protect ourselves if we can’t block Google?
You can’t block access to Google Drive in a modern business, but you can change how you approach security:
- HTTPS Inspection (SSL Inspection): The firewall must "unpack" encrypted data packets to see what’s really inside them.
- Behavioral Monitoring (EDR): A classic antivirus looks for signatures. An EDR (Endpoint Detection and Response) looks at behavior: "Why is Notepad trying to connect to the internet?"
- Frequency Analysis: A human doesn’t upload files at fixed intervals of exactly 30 seconds. An automated script does.
This technique of using legitimate services is called "Living off the Land." To understand the technical concept, you can consult the definition in Proofpoint’s references on Living off the Land tactics.
Conclusion
Security is no longer just about high walls (firewalls), but about smart surveillance cameras (behavioral monitoring). If your computer is acting strangely, even when accessing secure sites, ask for help.
Want to know if your network is hiding such invisible threats? We offer state-of-the-art EDR solutions and 24/7 IT monitoring services. Visit our contact page and scan your systems before it’s too late.
This material is part of Altanet’s educational series on digital security. Want to know what other risks you’re facing this year? See the complete list of cyber threats for 2026.




