logo

Microsoft Graph API Exploited for Stealthy Attacks

ID: 26f2eb4d-51bf-5733-baf3-c8db82714518

STIX ID: report--26f2eb4d-51bf-5733-baf3-c8db82714518

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-05-03

Date Updated: 2026-04-22

Author: do son

...
...

Attackers are abusing the Microsoft Graph API to camouflage C2 and data exfiltration inside legitimate Microsoft 365 traffic; the report highlights a Ukrainian incident where 'BirdyClient' (OneDriveBirdyClient) used OneDrive via Graph API as a hidden C2, references prior APT37 usage and tools like GraphStrike/Cobalt Strike, and urges monitoring API usage, detecting anomalous cloud transfers, and proactive threat intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.