Close Menu
    What's Hot

    Homeowners are suddenly pulling their houses off the market—and this is why

    With His New Museum, Obama Offers a Trip to a Parallel America

    Opinion | The Strait of Hormuz Is Blocked. The World Is Adjusting.

    Facebook X (Twitter) Instagram
    Trending
    • Homeowners are suddenly pulling their houses off the market—and this is why
    • With His New Museum, Obama Offers a Trip to a Parallel America
    • Opinion | The Strait of Hormuz Is Blocked. The World Is Adjusting.
    • The Iran War Is Decarbonizing the Global South
    • These two founders left Goldman and Meta to build voice AI for markets everyone else overlooked
    • Datadog, Inc. (DDOG) Presents at Bank of America 2026 Global Technology Conference Transcript
    • USWNT’s Trinity Rodman on Triple Espresso: ‘Having my sisters back is amazing’
    • Amazon will show AI product images when you search for some reason
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

    adminBy adminApril 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 22, 2026Cyber Espionage / Malware

    Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

    The threat actor known as Harvester has been attributed to a new Linux version of its GoGra backdoor deployed as part of attacks likely targeting entities in South Asia.

    “The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel, allowing it to bypass traditional perimeter network defenses,” the Symantec and Carbon Black Threat Hunter Team said in a report shared with The Hacker News.

    The cybersecurity company said it identified artifacts uploaded to the VirusTotal platform from India and Afghanistan, suggesting that the two countries may be the target of the espionage activity.

    Cybersecurity

    Harvester was first publicly documented by Symantec in late 2021, linking it to an information-stealing campaign aimed at telecommunications, government, and information technology sectors in South Asia since June 2021, using a bespoke implant called Graphon that used the Microsoft Graph API for C2.

    Subsequent activity flagged in August 2024 connected the hacking group to an attack targeting an unnamed media organization in South Asia with a never-before-seen Go-based backdoor called GoGra. The latest findings suggest that the adversary is continuing to expand its toolset beyond Windows and infecting Linux machines with a new variant of the same backdoor.

    The attacks employ social engineering to trick victims into opening ELF binaries disguised as PDF documents. The dropper then proceeds to display a lure document while stealthily running the backdoor.

    Like its Windows counterpart, the Linux version of GoGra abuses Microsoft’s cloud infrastructure to contact a specific Outlook mailbox folder named “Zomato Pizza” every two seconds using Open Data Protocol (OData) queries. The backdoor scans the inbox for incoming email messages with a subject line starting with the word “Input.”

    Cybersecurity

    Once an email matching the criteria is received, it decrypts the Base64-encoded message body and executes it as shell commands using “/bin/bash.” The results of the execution are sent back to the operator in an email message with the subject line “Output.” After the exfiltration step is complete, the implant wipes the original tasking message to cover up the tracks.

    “Despite using different deployment architectures and operating systems, the underlying C2 logic remains unchanged,” Symantec and Carbon Black said, adding the teams “also identified several matching, hard-coded spelling errors across both platforms, which points towards the same developer being behind both tools.”

    “The use of a new Linux backdoor shows that Harvester is continuing to expand its toolset and actively develop new tooling in order to go after a wider range of victims and machines.”

    API Asia Backdoor deploys GoGra Graph Harvester Linux Microsoft South
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article‘Free Births’ Are a New Pregnancy Trend. Critics Warn About Serious Risks.
    Next Article Anthropic’s Mythos rollout has missed America’s cybersecurity agency
    admin
    • Website

    Related Posts

    The Iran War Is Decarbonizing the Global South

    June 4, 2026

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

    June 4, 2026

    Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

    June 4, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Homeowners are suddenly pulling their houses off the market—and this is why

    With His New Museum, Obama Offers a Trip to a Parallel America

    Opinion | The Strait of Hormuz Is Blocked. The World Is Adjusting.

    The Iran War Is Decarbonizing the Global South

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by