New GoGra malware for Linux uses Microsoft Graph API for comms
ID: 42aa4a03-94d9-5b10-aacd-f56ba22fd51a
STIX ID: report--42aa4a03-94d9-5b10-aacd-f56ba22fd51a
Feed Name: Bleeping Computer
Symantec researchers detail a Linux GoGra backdoor used by the Harvester APT that authenticates to Microsoft cloud using hardcoded Azure AD credentials to access an Outlook mailbox (folder named "Zomato Pizza") via Microsoft Graph API, polling for AES-CBC-encrypted, base64-encoded commands with subjects starting "Input" and returning AES-encrypted execution results in reply emails "Output"; the dropper establishes persistence via systemd and an XDG autostart entry, disguises ELF payloads as PDFs, and deletes processed command emails to reduce visibility, while code similarities with the Windows variant indicate a shared developer and expanding targeting of telecom, government, and IT organizations in South Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
