Signal

Linux GoGra backdoor uses Microsoft Graph API for stealthy communications

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-22 10:00 UTCUpdated 2026-04-22 15:28 UTC
rss
malwarethreat_actorslinuxsecurity_tooling
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
New GoGra malware for Linux uses Microsoft Graph API for comms
bleepingcomputer_all · News · bleepingcomputer.com · 2026-04-22 10:00 UTC
limited source diversity in top sources
Overview

The Harvester threat actor has introduced a Linux version of its GoGra backdoor malware, which uses the Microsoft Graph API and Outlook inboxes to establish a covert command-and-control channel. By exploiting trusted Microsoft cloud services, the malware bypasses conventional network defenses, complicating detection and response efforts. This campaign appears to focus on targets in South Asia, highlighting regional threat activity employing advanced evasion techniques.

Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Recent discovery of Linux GoGra variant shows evolving malware tactics.
  • Harvester's deployment signals active campaigns exploiting cloud services.
  • Understanding this method aids defenders in adapting security controls promptly.
Why it matters
  • Attackers leveraging legitimate cloud APIs complicate detection and response efforts.
  • Use of trusted Microsoft infrastructure allows malware to bypass traditional network defenses.
  • Targeting South Asia indicates regional threat actor activity with advanced evasion techniques.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • The Linux GoGra backdoor uses Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel.
How sources frame it
  • Security Researchers: neutral
This report highlights the evolving use of legitimate cloud APIs by malware to evade detection, emphasizing the need for defenders to monitor trusted service abuse.
All evidence
All evidence
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
thehackernews · thehackernews.com · 2026-04-22 15:28 UTC
New GoGra malware for Linux uses Microsoft Graph API for comms
bleepingcomputer_all · bleepingcomputer.com · 2026-04-22 10:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • thehackernews (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • bleepingcomputer.com (1)