logo

Harvester APT Expands Spying Operations with New GoGra Linux Malware

ID: 29fbb266-2316-5920-899c-efe69b0fb4c7

STIX ID: report--29fbb266-2316-5920-899c-efe69b0fb4c7

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Deeba Ahmed

...
...

Researchers report that the nation-state-backed APT “Harvester” has deployed a new Linux backdoor called GoGra to spy on systems in India and Afghanistan; the malware uses social-engineered ELF attachments that display fake PDFs, persists under ~/.config/systemd/user/userservice as a Conky impersonator, and performs covert C2 over Microsoft Graph/Outlook using stolen Azure AD credentials and encrypted commands (subjects “Input”/“Output”), with similarities to the Windows backdoor Graphon indicating the same developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.