logo

Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

ID: 83b46e9a-7564-59b0-9372-871d201aa06b

STIX ID: report--83b46e9a-7564-59b0-9372-871d201aa06b

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Harvester, an APT linked to espionage in South Asia, has deployed a new Linux Go-based backdoor named GoGra that uses Microsoft Graph API and Outlook mailboxes (folder "Zomato Pizza") as a covert C2 channel; the implant executes Base64-encoded shell commands from emails and exfiltrates results back via email. The attack uses ELF droppers disguised as PDFs to display lures while running the backdoor, and artifacts seen on VirusTotal from India and Afghanistan suggest targeted activity and an expansion of Harvester's toolset beyond Windows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.