logo

Microsoft Graph API misused by new GoGra Linux malware for hidden communication

ID: 1ee3f897-ec66-5764-ab6c-11712ee9dabb

STIX ID: report--1ee3f897-ec66-5764-ab6c-11712ee9dabb

Feed Name: Security Affairs

Threat Score
86/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Pierluigi Paganini

...
...

A new Linux variant of the GoGra backdoor, attributed to the Harvester APT, uses hardcoded Azure AD credentials to obtain OAuth2 tokens and polls a specific Outlook mailbox via Microsoft Graph API (folder named "Zomato Pizza") to receive AES-CBC encrypted commands and return encrypted results, deleting messages to evade detection; researchers report cross-platform code similarity with the Windows variant and early targeting evidence from South Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.