logo

Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications

ID: 83b1a98b-7a28-54bb-95bc-33773eb29468

STIX ID: report--83b1a98b-7a28-54bb-95bc-33773eb29468

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-03

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Symantec researchers and industry reports describe increasing abuse of the Microsoft Graph API and OneDrive as covert command-and-control channels by multiple nation-state-aligned groups since 2021–2022. The report highlights observed implants such as Graphon and a newly documented BirdyClient (aka OneDriveBirdyClient) using a DLL named vxdiff.dll to upload/download to OneDrive, and warns that attackers may leverage trusted cloud services and compromised third-party privileged access to execute commands on VMs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.