logo

New GoGra malware for Linux uses Microsoft Graph API for comms

ID: 42aa4a03-94d9-5b10-aacd-f56ba22fd51a

STIX ID: report--42aa4a03-94d9-5b10-aacd-f56ba22fd51a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Bill Toulas

...
...

Symantec researchers detail a Linux GoGra backdoor used by the Harvester APT that authenticates to Microsoft cloud using hardcoded Azure AD credentials to access an Outlook mailbox (folder named "Zomato Pizza") via Microsoft Graph API, polling for AES-CBC-encrypted, base64-encoded commands with subjects starting "Input" and returning AES-encrypted execution results in reply emails "Output"; the dropper establishes persistence via systemd and an XDG autostart entry, disguises ELF payloads as PDFs, and deletes processed command emails to reduce visibility, while code similarities with the Windows variant indicate a shared developer and expanding targeting of telecom, government, and IT organizations in South Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.