logo

Hackers Use Outlook Mailboxes to Hide Linux GoGra Backdoor Communications

ID: 1819f74f-9c21-5209-b32c-09c074b1b001

STIX ID: report--1819f74f-9c21-5209-b32c-09c074b1b001

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Tushar Subhra Dutta

...
...

A nation-state–linked APT known as Harvester has developed a Linux GoGra backdoor that abuses Microsoft Graph and real Outlook mailboxes (folder named "Zomato Pizza") as a covert C2 channel; the malware uses hardcoded Azure AD app credentials to obtain OAuth2 tokens, polls for emails with subjects starting with "Input", executes AES-CBC encrypted commands, returns encrypted results as "Output" emails, and deletes command messages to hide activity. Initial access was via social-engineering lures delivering ELF binaries masquerading as PDFs, with persistence through a systemd user unit and XDG autostart entry, and initial samples observed from India and Afghanistan indicating South Asia targeting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.