logo

Harvester APT Goes Cross-Platform: New Linux Backdoor Abuses Microsoft Graph API

ID: 6b638510-83c8-5784-b3f4-292531ef5e9a

STIX ID: report--6b638510-83c8-5784-b3f4-292531ef5e9a

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

**Executive Summary:** Symantec and Carbon Black researchers report that the Harvester APT has developed a highly evasive Linux variant of its GoGra backdoor that uses legitimate Microsoft Graph API and Outlook mailboxes as a covert C2 channel, employs hardcoded Azure AD credentials to obtain OAuth tokens, polls a folder named "Zomato Pizza" for AES-CBC encrypted commands, executes tasks via /bin/bash, and maintains persistence via systemd and XDG autostart entries; the Linux and Windows variants share near-identical code and developer typos, indicating cross-platform expansion of this nation-state espionage campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.