Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor

74ac41406ce7a7aa992f68b4b3042f980027526f33ec6c8d84cb26f20495c9dc

TLP:CLEAR
Active

SHA-256 Hash

Description

The Harvester APT group has developed a new Linux version of its GoGra backdoor that uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel. The malware employs social engineering lures with tailored decoy documents, masquerading malicious ELF files as standard documents. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The backdoor uses hardcoded Azure AD credentials to poll a specific mailbox folder at two-second intervals, executing commands received via encrypted emails and exfiltrating results through reply messages. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating Harvester's multi-platform development strategy and continued focus on South Asian espionage operations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor
Pattern Type
STIX
Confidence
75%
Valid From
May 6, 2026 04:49
Total Sightings
0
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 74ac41406ce7a7aa992f68b4b3042f980027526f33ec6c8d84cb26f20495c9dc

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.