Outlook Mailboxes Abused to Conceal Linux GoGra Backdoor Traffic
ID: 46028890-48c7-5c6b-a94e-83460c9e389d
STIX ID: report--46028890-48c7-5c6b-a94e-83460c9e389d
Feed Name: GBHackers
Threat Score
Executive Summary: Researchers attributed a cross-platform Harvester APT campaign to a new Linux GoGra backdoor that authenticates to Outlook mailboxes via hardcoded Azure AD credentials to receive encrypted commands and exfiltrate results; the implant uses social-engineered documents and a Go dropper with systemd persistence, shares keys and code with a Windows variant, and targets organizations in South Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
