Sources: 
Harvester's new Linux GoGra malware employs the Microsoft Graph API for covert command-and-control operations, marking a significant evolution in its espionage tactics. This malware was detected primarily in South Asia, with initial samples traced back to India and Afghanistan.
The
GoGra backdoor operates stealthily, leveraging legitimate Microsoft infrastructure, including Outlook mailboxes, to achieve its objectives.
It checks an Outlook folder named 'Zomato Pizza' every two seconds for commands, communicating in a manner that blends in with normal traffic to avoid detection.
Symantec's analysis reveals that the malware utilizes hardcoded Azure Active Directory credentials to authenticate with Microsoft's cloud services and acquires OAuth2 tokens. After identifying emails marked with subjects like 'Input,' it decrypts commands using Base64 and AES-CBC encryption before executing them locally on infected systems.
This Linux variant shares an almost identical codebase with its Windows counterpart, indicating Harvester’s multi-platform strategy for espionage. Notably, Harvester has been actively involved since at least 2021, consistently targeting government, enterprise, and telecom sectors in South Asia.
Cybersecurity experts warn organizations to bolster defenses against such sophisticated threats, as traditional security measures are increasingly rendered ineffective by malware using trusted cloud platforms, raising alarms over its expanding operational scope and evolving techniques.
Sources: 
A new Linux variant of the GoGra malware, developed by the state-linked Harvester group, exploits the Microsoft Graph API for covert operations. Targeting South Asia, it utilizes Outlook mailboxes for command-and-control, utilizing hardcoded Azure credentials for authentication, making detection difficult for cybersecurity tools.