Harvester APT Goes Cross-Platform: New Linux Backdoor Abuses Microsoft Graph API
ID: 6b638510-83c8-5784-b3f4-292531ef5e9a
STIX ID: report--6b638510-83c8-5784-b3f4-292531ef5e9a
Feed Name: securityonline.info
**Executive Summary:** Symantec and Carbon Black researchers report that the Harvester APT has developed a highly evasive Linux variant of its GoGra backdoor that uses legitimate Microsoft Graph API and Outlook mailboxes as a covert C2 channel, employs hardcoded Azure AD credentials to obtain OAuth tokens, polls a folder named "Zomato Pizza" for AES-CBC encrypted commands, executes tasks via /bin/bash, and maintains persistence via systemd and XDG autostart entries; the Linux and Windows variants share near-identical code and developer typos, indicating cross-platform expansion of this nation-state espionage campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
