logo

Microsoft Graph API Emerges as a Top Attacker Tool to Plot Data Theft

ID: 26e22fcd-1c85-5cd2-832e-5bc1035a5d07

STIX ID: report--26e22fcd-1c85-5cd2-832e-5bc1035a5d07

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2024-05-02

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Nation-state and espionage groups increasingly abuse Microsoft Graph and other Microsoft cloud services (notably OneDrive) to host command-and-control infrastructure; the report lists multiple malware families (e.g., BirdyClient, Bluelight, Backdoor.Graphican) and APTs (APT37, APT15, APT29, Harvester) observed using this technique and advises tightening tenant controls and blocking unsanctioned cloud account access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.