“Google Drive” on Duplicati uses that API. Although I don’t recommend it, you can also have Duplicati use the file interface that your Google Drive probably provides.
The security issue either way is that malware that gets on your machine could harm any files visible on system, including ones easily accessed as files on Google Drive.
What makes it worse is the multiple-machine convenience of Google Drive provides many potential access paths. Easy for you, but also easy for anything getting in one.
Using a less easily accessed online destination means malware will have a tougher time destroying backups. Fully offline is hard on malware, but also hard on your use.
Using remote file locking is almost as good as online gets, but takes some setup.
Which cloud? If you mean Google Drive, and the backup will go to the same area, that’s almost never a safe plan, as damage to that area can wipe out both at once.
Avoid getting into situations where all the copies can be simultaneously destroyed. Unfortunately, this works against local offline (better against malware, but not fires).
You should decide how much it’s worth to reduce risk of losing data. More backups stored in separate places can reduce loss risks. See “3-2-1 rule” and its variations.
You can occasionally sync a cloud to a usually-offline USB drive to increase safety.
SyncTool can help with that. Cryptomator use might use Google Drive mirroring, so
you just make your own manual mirror with any tool sometime when state is stable.
Or you could run occasional separate backup to reduce danger from software error.
This has spoken mostly about damage to destination. Except for file locking, that’s
not something Duplicati can solve. Its encryption can reduce risks from file reading,
however if there’s already malware on your machine as you, I think it can read files.
I’m not a Cryptomator expert, but they have their own forum where you can discuss.
It shouldn’t be connected to anything, especially attacker-controlled computer,
which might be your computer. A totally compromised computer is bad news.
What Cryptomator Is Not has similar warning about having infected computer.
Since you said “strongest”, a question is how far towards that is it worth going?
Perfection is impossible, and sometimes malware is just going after easy attack
such as ransomware encrypting all files it finds. Skilled humans could do worse,
however they are scarcer, so probably will go after targets that are worth hitting.
In my view, attacker needs to be cost-effective. Same for you on defensive side.