Microsoft Graph API misused by new GoGra Linux malware for hidden communication
ID: 1ee3f897-ec66-5764-ab6c-11712ee9dabb
STIX ID: report--1ee3f897-ec66-5764-ab6c-11712ee9dabb
Feed Name: Security Affairs
Threat Score
A new Linux variant of the GoGra backdoor, attributed to the Harvester APT, uses hardcoded Azure AD credentials to obtain OAuth2 tokens and polls a specific Outlook mailbox via Microsoft Graph API (folder named "Zomato Pizza") to receive AES-CBC encrypted commands and return encrypted results, deleting messages to evade detection; researchers report cross-platform code similarity with the Windows variant and early targeting evidence from South Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
