Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
    Cybersecurity

    Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

    adminBy adminApril 22, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 22, 2026Cyber Espionage / Malware

    The threat actor known as Harvester has been attributed to a new Linux version of its GoGra backdoor deployed as part of attacks likely targeting entities in South Asia.

    “The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel, allowing it to bypass traditional perimeter network defenses,” the Symantec and Carbon Black Threat Hunter Team said in a report shared with The Hacker News.

    The cybersecurity company said it identified artifacts uploaded to the VirusTotal platform from India and Afghanistan, suggesting that the two countries may be the target of the espionage activity.

    Harvester was first publicly documented by Symantec in late 2021, linking it to an information-stealing campaign aimed at telecommunications, government, and information technology sectors in South Asia since June 2021, using a bespoke implant called Graphon that used the Microsoft Graph API for C2.

    Subsequent activity flagged in August 2024 connected the hacking group to an attack targeting an unnamed media organization in South Asia with a never-before-seen Go-based backdoor called GoGra. The latest findings suggest that the adversary is continuing to expand its toolset beyond Windows and infecting Linux machines with a new variant of the same backdoor.

    The attacks employ social engineering to trick victims into opening ELF binaries disguised as PDF documents. The dropper then proceeds to display a lure document while stealthily running the backdoor.

    Like its Windows counterpart, the Linux version of GoGra abuses Microsoft’s cloud infrastructure to contact a specific Outlook mailbox folder named “Zomato Pizza” every two seconds using Open Data Protocol (OData) queries. The backdoor scans the inbox for incoming email messages with a subject line starting with the word “Input.”

    Once an email matching the criteria is received, it decrypts the Base64-encoded message body and executes it as shell commands using “/bin/bash.” The results of the execution are sent back to the operator in an email message with the subject line “Output.” After the exfiltration step is complete, the implant wipes the original tasking message to cover up the tracks.

    “Despite using different deployment architectures and operating systems, the underlying C2 logic remains unchanged,” Symantec and Carbon Black said, adding the teams “also identified several matching, hard-coded spelling errors across both platforms, which points towards the same developer being behind both tools.”

    “The use of a new Linux backdoor shows that Harvester is continuing to expand its toolset and actively develop new tooling in order to go after a wider range of victims and machines.”

    API Asia backdoor Deploys GoGra Graph Harvester Linux Microsoft South
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow Data Coach Claire Uses Product Research to Outperform Brand Samples by 3x and Stay on Track for $100K
    Next Article It’s the end of set-and-forget security
    admin
    • Website

    Related Posts

    DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’

    April 22, 2026

    Claude Mythos finds 271 Firefox flaws, Mozilla believes it shifts security toward defenders

    April 22, 2026

    The Scam Economy Has a Hiring Process

    April 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    3 Huge Ways AI Impacts Your Content Strategy & How to Pivot

    April 22, 2026

    Roboto 3.6.00.0 by Samsung Electronics Co., Ltd.

    April 22, 2026

    DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’

    April 22, 2026

    EFF Sues DHS and ICE For Records on Subpoenas Seeking to Unmask Online Critics

    April 22, 2026
    Categories
    • Blogging (67)
    • Cybersecurity (1,448)
    • Privacy & Online Earning (179)
    • SEO & Digital Marketing (884)
    • Tech Tools & Mobile / Apps (1,736)
    • WiFi / Internet & Networking (240)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    3 Huge Ways AI Impacts Your Content Strategy & How to Pivot

    April 22, 2026

    Roboto 3.6.00.0 by Samsung Electronics Co., Ltd.

    April 22, 2026

    DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’

    April 22, 2026
    Most Popular
    • 3 Huge Ways AI Impacts Your Content Strategy & How to Pivot
    • Roboto 3.6.00.0 by Samsung Electronics Co., Ltd.
    • DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’
    • EFF Sues DHS and ICE For Records on Subpoenas Seeking to Unmask Online Critics
    • Google Ads adds app consent diagnostics to improve privacy performance
    • Google expands its browser assistant to more countries, and I can’t ignore how convenient this is
    • It’s the end of set-and-forget security
    • Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.