Harvester deploys new Linux GoGra malware, leveraging Microsoft Graph API for covert operations targeting South Asia.

Harvester has introduced a Linux variant of the GoGra malware that exploits the Microsoft Graph API for covert command-and-control capabilities. This new tool is part of an expanded focus on targeting South Asia as a key operational area.

Sources:
The420.in+2
Trending 1h ago
Tab background
Sources: The420.in
Harvester's new Linux GoGra malware employs the Microsoft Graph API for covert command-and-control operations, marking a significant evolution in its espionage tactics. This malware was detected primarily in South Asia, with initial samples traced back to India and Afghanistan.

The GoGra backdoor operates stealthily, leveraging legitimate Microsoft infrastructure, including Outlook mailboxes, to achieve its objectives. It checks an Outlook folder named 'Zomato Pizza' every two seconds for commands, communicating in a manner that blends in with normal traffic to avoid detection.

Symantec's analysis reveals that the malware utilizes hardcoded Azure Active Directory credentials to authenticate with Microsoft's cloud services and acquires OAuth2 tokens. After identifying emails marked with subjects like 'Input,' it decrypts commands using Base64 and AES-CBC encryption before executing them locally on infected systems.

This Linux variant shares an almost identical codebase with its Windows counterpart, indicating Harvester’s multi-platform strategy for espionage. Notably, Harvester has been actively involved since at least 2021, consistently targeting government, enterprise, and telecom sectors in South Asia.

Cybersecurity experts warn organizations to bolster defenses against such sophisticated threats, as traditional security measures are increasingly rendered ineffective by malware using trusted cloud platforms, raising alarms over its expanding operational scope and evolving techniques.
Sources: The420.in
A new Linux variant of the GoGra malware, developed by the state-linked Harvester group, exploits the Microsoft Graph API for covert operations. Targeting South Asia, it utilizes Outlook mailboxes for command-and-control, utilizing hardcoded Azure credentials for authentication, making detection difficult for cybersecurity tools.
Section 1 background
The Headline

Harvester's New Linux GoGra Malware Unveiled

Key Facts
  • Harvester has developed a new, highly-evasive, Linux version of its malware, using the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel.1
  • The new Linux variant is part of a sophisticated espionage framework attributed to the state-backed group known as 'Harvester', which has been active since 2021.The420.in
  • The GoGra malware exploits Microsoft Graph API for covert operations, making detection significantly more challenging for traditional security measures.The420.in
  • GoGra continuously monitors a mailbox folder named 'Zomato Pizza' for emails with subjects starting with 'Input' containing encrypted commands.The420.in
  • The malware uses hardcoded Azure Active Directory credentials and obtains OAuth2 tokens to interact with Outlook mailboxes, effectively blending malicious activity with legitimate cloud traffic.The420.in
Section 2 background
Background Context

Context on Harvester and GoGra Malware

Key Facts
  • Security analysis revealed that the Linux variant shares an almost identical codebase with its Windows counterpart, showcasing Harvester's multi-platform development strategy.The420.in
  • Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets.1
  • Harvester has historically targeted victims in South Asia and continues to focus on this region for espionage.1
  • Cybersecurity experts describe GoGra's techniques as a highly advanced form of stealth communication, exploiting trusted cloud platforms to bypass security monitoring.The420.in
Article not found
CuriousCats.ai

Article

Source Citations