Exposing Godlike12 Backdoor Using Covert Google Drive C2 Channels
In today’s rapidly evolving threat landscape, adversaries are engineering malware to blend into trusted cloud platforms.

In today’s rapidly evolving threat landscape, adversaries are engineering malware to blend into trusted cloud platforms. One notable example is Godlike12, a sophisticated Windows backdoor that uses Google Drive as a Command and Control (C2) channel, bypassing traditional network-based detection systems.
At Alpha Cyber, we specialize in identifying and visualizing these covert operations through advanced infrastructure mapping services, which are essential in detecting threats that abuse legitimate cloud services.
Threat Summary: What Is Godlike12?
Godlike12 is a stealthy Windows malware used in targeted attacks across Asia-Pacific. Unlike conventional backdoors that rely on fixed IPs or domain-based infrastructure, Godlike12 leverages Google’s cloud services for stealth and resilience.
Key Capabilities:
- Command Retrieval via Google Drive: Fetches tasking documents via the Drive API
- Exfiltration through Cloud Storage: Sends victim system data as hidden files to Drive
- Kernel-Level Evasion: Conceals activity from traditional AV and EDR tools
- Staged Deployment Architecture: Downloads and executes additional payloads post-infection
- Persistent Execution: Registers tasks and registry keys for automatic execution at boot
Infrastructure Mapping: Godlike12’s Infection Chain
Our internal analysis maps Godlike12’s infection infrastructure into a multi-stage kill chain:
Stage 1: Initial Stager
The infection begins with a dropper disguised as a Flash installer (flashplayer32ppi_xa_install.exe). This executable:
- Drops and executes a component named Intelsyc.exe
- Connects to
adobeflash31_install.ddns[.]infoto fetch configuration or a potential kill switch - Establishes persistence by creating a Windows Scheduled Task under the name Intelsyc
Stage 2: Payload Deployment
Once executed, the stager writes the main payload, flashdriver.exe, to: C:\ProgramData\Adobe\flashdriver.exe It also writes a registry key to maintain persistence:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\flashdriver
Stage 3: Covert C2 Channel via Google Drive
This is where Godlike12 differentiates itself technologically:
- It authenticates with the Google Drive API v3 using hardcoded tokens or OAuth credentials
- System fingerprinting data (hostname, user, OS version) is written to a file and uploaded
- Commands are received through files dropped into a specific Google Drive folder
This traffic blends in with legitimate enterprise cloud use, evading proxy inspection and firewall rules
Stealth and Resilience
Using Google infrastructure offers attackers:
- Encryption by default
- Redundancy and uptime
- Legitimacy to bypass endpoint and perimeter filtering
Unlike static C2 IPs, blocking Google APIs risks breaking business-critical services, making detection much harder without behavioral monitoring and infrastructure mapping.
Indicators of Compromise (IOCs)
Below is a list of IOCs identified through our infrastructure mapping and malware analysis pipeline. Organizations should ingest these into their SIEM, EDR, and network defense platforms for immediate detection and blocking.
| Type | Value | Details / Notes |
|---|---|---|
| Malware / File Hash | BEC4482890A89F0184B463C727709D53 | Godlike12 backdoor sample (flashdriver.exe) |
| Malware / File Hash | 6DC5F8282DF76F4045F75FEA3277DF41 | Intelsyc stager sample |
| Filenames | flashdriver.exe | Executable name of the backdoor |
| Drop Path | C:\ProgramData\Adobe\flashdriver.exe | Backdoor location |
| Drop Path | C:\ProgramData\Intel\Intelsyc.exe | Stager drop location |
| Persistence | HKLM\Software\Microsoft\Windows\CurrentVersion\Run\flashdriver | Registry entry used for persistence |
| Scheduled Task | Intelsyc | Scheduled Task name used to launch stager |
| C2 Channel | Google Drive API v3 | Covert C2 communications over encrypted HTTPS |
| Suspicious Domain | adobeflash31_install.ddns[.]info | Used for kill switch or secondary config retrieval |
Our Approach to Covert Infrastructure Detection
Our infrastructure threat mapping service enables clients to uncover stealthy threat operations through:
- Endpoint Execution Flow Mapping
- Persistence Vector Discovery
- Cloud C2 Channel Monitoring
- Network Anomaly Detection in SaaS Traffic
Automated IOC Extraction & Alerting
By integrating host-level telemetry, process tree analysis, and cloud service inspection, we help organizations see through legitimate-looking traffic and identify attacker activity embedded in their environment.
Final Thoughts
Godlike12 exemplifies the future of malware covert, cloud-based, and evasive. Organizations must go beyond static blacklists and begin mapping the infrastructure of threats, especially those leveraging legitimate cloud APIs.
If your organization uses cloud storage or collaboration platforms, now is the time to evaluate how they are being monitored.
Start your infrastructure visibility assessment here



