Microsoft Graph API Emerges as a Top Attacker Tool to Plot Data Theft
ID: 26e22fcd-1c85-5cd2-832e-5bc1035a5d07
STIX ID: report--26e22fcd-1c85-5cd2-832e-5bc1035a5d07
Feed Name: Dark Reading
Threat Score
Nation-state and espionage groups increasingly abuse Microsoft Graph and other Microsoft cloud services (notably OneDrive) to host command-and-control infrastructure; the report lists multiple malware families (e.g., BirdyClient, Bluelight, Backdoor.Graphican) and APTs (APT37, APT15, APT29, Harvester) observed using this technique and advises tightening tenant controls and blocking unsanctioned cloud account access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
