Alpha Cyber

Exposing Godlike12 Backdoor Using Covert Google Drive C2 Channels

In today’s rapidly evolving threat landscape, adversaries are engineering malware to blend into trusted cloud platforms.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Godlike12 Backdoor Malware

In today’s rapidly evolving threat landscape, adversaries are engineering malware to blend into trusted cloud platforms. One notable example is Godlike12, a sophisticated Windows backdoor that uses Google Drive as a Command and Control (C2) channel, bypassing traditional network-based detection systems.

At Alpha Cyber, we specialize in identifying and visualizing these covert operations through advanced infrastructure mapping services, which are essential in detecting threats that abuse legitimate cloud services.

Threat Summary: What Is Godlike12?

Godlike12 is a stealthy Windows malware used in targeted attacks across Asia-Pacific. Unlike conventional backdoors that rely on fixed IPs or domain-based infrastructure, Godlike12 leverages Google’s cloud services for stealth and resilience.

Key Capabilities:

  • Command Retrieval via Google Drive: Fetches tasking documents via the Drive API
  • Exfiltration through Cloud Storage: Sends victim system data as hidden files to Drive
  • Kernel-Level Evasion: Conceals activity from traditional AV and EDR tools
  • Staged Deployment Architecture: Downloads and executes additional payloads post-infection
  • Persistent Execution: Registers tasks and registry keys for automatic execution at boot

Infrastructure Mapping: Godlike12’s Infection Chain

Our internal analysis maps Godlike12’s infection infrastructure into a multi-stage kill chain:

Stage 1: Initial Stager

The infection begins with a dropper disguised as a Flash installer (flashplayer32ppi_xa_install.exe). This executable:

  • Drops and executes a component named Intelsyc.exe
  • Connects to adobeflash31_install.ddns[.]info to fetch configuration or a potential kill switch
  • Establishes persistence by creating a Windows Scheduled Task under the name Intelsyc

Stage 2: Payload Deployment

Once executed, the stager writes the main payload, flashdriver.exe, to: C:\ProgramData\Adobe\flashdriver.exe It also writes a registry key to maintain persistence:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\flashdriver

Stage 3: Covert C2 Channel via Google Drive

This is where Godlike12 differentiates itself technologically:

  • It authenticates with the Google Drive API v3 using hardcoded tokens or OAuth credentials
  • System fingerprinting data (hostname, user, OS version) is written to a file and uploaded
  • Commands are received through files dropped into a specific Google Drive folder

This traffic blends in with legitimate enterprise cloud use, evading proxy inspection and firewall rules

Stealth and Resilience

Using Google infrastructure offers attackers:

  • Encryption by default
  • Redundancy and uptime
  • Legitimacy to bypass endpoint and perimeter filtering

Unlike static C2 IPs, blocking Google APIs risks breaking business-critical services, making detection much harder without behavioral monitoring and infrastructure mapping.

Indicators of Compromise (IOCs)

Below is a list of IOCs identified through our infrastructure mapping and malware analysis pipeline. Organizations should ingest these into their SIEM, EDR, and network defense platforms for immediate detection and blocking.

TypeValueDetails / Notes
Malware / File HashBEC4482890A89F0184B463C727709D53Godlike12 backdoor sample (flashdriver.exe)
Malware / File Hash6DC5F8282DF76F4045F75FEA3277DF41Intelsyc stager sample
Filenamesflashdriver.exeExecutable name of the backdoor
Drop PathC:\ProgramData\Adobe\flashdriver.exeBackdoor location
Drop PathC:\ProgramData\Intel\Intelsyc.exeStager drop location
PersistenceHKLM\Software\Microsoft\Windows\CurrentVersion\Run\flashdriverRegistry entry used for persistence
Scheduled TaskIntelsycScheduled Task name used to launch stager
C2 ChannelGoogle Drive API v3Covert C2 communications over encrypted HTTPS
Suspicious Domainadobeflash31_install.ddns[.]infoUsed for kill switch or secondary config retrieval

Our Approach to Covert Infrastructure Detection

Our infrastructure threat mapping service enables clients to uncover stealthy threat operations through:

  • Endpoint Execution Flow Mapping
  • Persistence Vector Discovery
  • Cloud C2 Channel Monitoring
  • Network Anomaly Detection in SaaS Traffic

Automated IOC Extraction & Alerting

By integrating host-level telemetry, process tree analysis, and cloud service inspection, we help organizations see through legitimate-looking traffic and identify attacker activity embedded in their environment.

Final Thoughts

Godlike12 exemplifies the future of malware covert, cloud-based, and evasive. Organizations must go beyond static blacklists and begin mapping the infrastructure of threats, especially those leveraging legitimate cloud APIs.

If your organization uses cloud storage or collaboration platforms, now is the time to evaluate how they are being monitored.

Start your infrastructure visibility assessment here

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]