logo

Outlook Mailboxes Abused to Conceal Linux GoGra Backdoor Traffic

ID: 46028890-48c7-5c6b-a94e-83460c9e389d

STIX ID: report--46028890-48c7-5c6b-a94e-83460c9e389d

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Divya

...
...

Executive Summary: Researchers attributed a cross-platform Harvester APT campaign to a new Linux GoGra backdoor that authenticates to Outlook mailboxes via hardcoded Azure AD credentials to receive encrypted commands and exfiltrate results; the implant uses social-engineered documents and a Go dropper with systemd persistence, shares keys and code with a Windows variant, and targets organizations in South Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.