Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API Emmie Evans April 22, 2026

Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

The threat actor known as Harvester has been attributed to a new Linux version of its GoGra backdoor deployed as part of attacks likely targeting entities in South Asia.
“The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel, allowing it to bypass traditional perimeter network defenses,” the Symantec and Carbon Black Threat Hunter

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top