RAT
iDrive
iDrive is a cloud backup and remote management software that has recently been observed being leveraged in social engineering campaigns, including invitation-themed and Social Security-related phishing lures, to establish unauthorized remote access on victim endpoints prior to the deployment of ScreenConnect. The tool installs as a Windows Scheduled Task and has been used as an initial access mechanism and staging point for secondary RMM deployment.
Tool overview
- Category
- RAT
- Research authors
- Michael Haag
- Created
- 2026-01-21
- Last modified
- 2026-01-21
- Privileges
- User
- Free / availability
- No
- Verification required
- Commercial
- Supported platforms
Android
Linux
Windows
iOS
macOS
Capabilities
Executables & installation paths
- Filename
- IDriveWinSetup.exe
- OriginalFileName
- Not recorded
- Description
- iDrive Windows installer executable (observed in phishing campaigns)
- Filename
- IDriveEClassic.exe
- OriginalFileName
- Not recorded
- Description
- iDrive Classic client executable
- Filename
- id_tray.exe
- OriginalFileName
- Not recorded
- Description
- iDrive system tray application
- Filename
- IDComponent.dll
- OriginalFileName
- Not recorded
- Description
- iDrive component library
Installation paths
C:\ProgramData\IDrive\*
C:\Program Files\IDrive\*
C:\Program Files (x86)\IDrive\*
C:\Users\*\AppData\Local\IDrive\*
C:\Users\*\Downloads\IDriveWinSetup.exe
IDriveWinSetup.exe
IDriveEClassic.exe
id_tray.exe
IDComponent.dll
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\IDrive\*
- Description
- iDrive installation and data directory (observed in threat intelligence)
- OS
- Windows
- File
- C:\Program Files\IDrive\*
- Description
- iDrive program files directory
- OS
- Windows
- File
- C:\Program Files (x86)\IDrive\*
- Description
- iDrive program files directory (32-bit)
- OS
- Windows
- File
- C:\Users\*\AppData\Local\IDrive\*
- Description
- iDrive user data and configuration
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 4688
- Description
- Process creation event for IDrive executables
- OS
- Windows
- EventID
- 4698
- Description
- Scheduled task creation event for iDrive
- OS
- Windows
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKEY_LOCAL_MACHINE\SOFTWARE\IDrive\*
- Description
- iDrive configuration registry keys
- OS
- Windows
- Path
- HKEY_CURRENT_USER\SOFTWARE\IDrive\*
- Description
- iDrive user configuration registry keys
- OS
- Windows
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains and API endpoints
- Domains
- idrive.com
- *.idrive.com
- api.idrive.com
- Ports
- 443
- 80
References
Acknowledgements
- Person
- 0xburgers
- Handle
- @0xburgers