New GoGra malware for Linux uses Microsoft Graph API for comms

New GoGra malware for Linux uses Microsoft Graph API for comms

A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery.

The malware is developed by Harvester, an espionage group believed to be state-baked, and is considered highly evasive due to its use of Microsoft Graph API to access mailbox data.

Harvester has been active since at least 2021 and is known to use custom malicious tools, such as backdoors and loaders in campaigns targeting telecommunications, government, and IT organizations in South Asia.

Read more: bleepingcomputer.com