216.73.216.226

APT Group Expands Toolset With New GoGra Linux Backdoor

· Published 22/04/2026 11:35 · Modified 22/04/2026 15:32

Export JSON

Essential information

Published
22/04/2026 11:35
Modified
22/04/2026 15:32
Tags
2026-04-22 azure ad abuse cross-platform gogra graphon linux backdoor microsoft graph api nation-state south asia espionage
Related entities
5 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 3 others

Description

The Harvester APT group has developed a highly-evasive Linux version of its backdoor that leverages and Outlook mailboxes as a covert command-and-control channel to bypass traditional network defenses. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The attackers use social engineering with tailored decoy documents masquerading as legitimate files, including references to Indian food delivery services. The backdoor uses hardcoded Azure AD credentials to poll mailboxes every two seconds, executing commands received via email and exfiltrating results back to operators. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating the group's multi-platform development strategy and continued expansion of capabilities targeting South Asia for espionage purposes.

External references