Harvester APT Group Unveils New GoGra Linux Backdoor Using Microsoft Graph API
ID: ae70e62c-ed8a-5cd9-8c4a-ce1f6596b369
STIX ID: report--ae70e62c-ed8a-5cd9-8c4a-ce1f6596b369
Feed Name: ThreatCluster
Threat Score
The Harvester APT has developed a Linux GoGra backdoor that uses Microsoft Graph API and Outlook mailboxes for covert C2, disguises ELF binaries as PDFs for initial access, and employs systemd/XDG autostart persistence; initial indicators point to targets in India and Afghanistan and researchers note code overlap with a Windows variant, indicating a coordinated espionage campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
