logo

Outlook Mailboxes Used to Conceal Linux GoGra Backdoor Traffic

ID: 286e16a1-dd8e-532b-aee8-b7b3bf9661e9

STIX ID: report--286e16a1-dd8e-532b-aee8-b7b3bf9661e9

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Mayura Kathir

...
...

A previously Windows-focused APT known as Harvester has deployed a new Linux variant of the GoGra backdoor that uses social-engineered lures and a Go-based dropper to establish persistence via systemd/XDG autostart. The backdoor authenticates to Microsoft services using hardcoded Azure AD credentials and uses Outlook mailbox polling (Graph API/OData) to receive AES-encrypted commands and exfiltrate results, deleting command emails after processing; researchers link the Linux and Windows variants by shared keys, code structure, and identical developer mistakes, with initial samples uploaded from India and Afghanistan.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.