Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications
ID: 83b1a98b-7a28-54bb-95bc-33773eb29468
STIX ID: report--83b1a98b-7a28-54bb-95bc-33773eb29468
Feed Name: The Hacker News
Symantec researchers and industry reports describe increasing abuse of the Microsoft Graph API and OneDrive as covert command-and-control channels by multiple nation-state-aligned groups since 2021–2022. The report highlights observed implants such as Graphon and a newly documented BirdyClient (aka OneDriveBirdyClient) using a DLL named vxdiff.dll to upload/download to OneDrive, and warns that attackers may leverage trusted cloud services and compromised third-party privileged access to execute commands on VMs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
