Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux GoGra Backdoor Targets South Asia via Microsoft API

Linux GoGra Backdoor Targets South Asia via Microsoft API

Posted on April 22, 2026 By CWS

The cyber threat group known as Harvester has been linked to a new Linux variant of its GoGra backdoor, reportedly aimed at South Asian entities. Utilizing the legitimate Microsoft Graph API, this malware circumvents traditional network defenses by using Outlook mailboxes as its covert command-and-control channel, according to a report shared by Symantec and Carbon Black Threat Hunter Team.

Targeted Regions and Tactics

Evidence of the malware was found on the VirusTotal platform, with uploads identified from India and Afghanistan, pointing to potential targets of this espionage operation. Harvester’s activities were first documented by Symantec in late 2021, revealing a campaign against telecommunications, government, and IT sectors in South Asia. The campaign employed a custom implant named Graphon, which also leveraged the Microsoft Graph API for command-and-control purposes.

Evolution of Harvester’s Toolset

In August 2024, Harvester’s activities were linked to an attack on a media organization in South Asia, deploying a novel Go-based backdoor known as GoGra. The recent discovery indicates Harvester’s expansion into infecting Linux systems with a new version of the backdoor, alongside its Windows counterpart. The attack strategy involves social engineering techniques that persuade targets to execute ELF binaries masquerading as PDF files, which then deploy the backdoor while displaying a decoy document.

Operational Mechanics and Cover-up

Similar to its Windows variant, the Linux GoGra backdoor exploits Microsoft’s cloud infrastructure, querying a designated Outlook mailbox folder named “Zomato Pizza” every two seconds via OData. It scans for emails with subject lines starting with “Input,” decrypts the Base64-encoded content, and executes the commands using “/bin/bash.” Once executed, results are emailed back with “Output” as the subject line. Post-exfiltration, the malware erases the original tasking message to eliminate traces.

Despite employing diverse operating systems and deployment methods, the core command-and-control logic of the GoGra backdoor remains consistent. Symantec and Carbon Black noted identical hard-coded spelling errors across both platforms, suggesting a single developer is responsible for both versions.

The introduction of a Linux backdoor underscores Harvester’s strategic efforts to broaden its attack arsenal, targeting a wider array of systems and victims. As cybersecurity landscapes evolve, vigilance and adaptive defense mechanisms remain crucial.

The Hacker News Tags:Backdoor, Carbon Black, cyber espionage, Cybersecurity, GoGra, Harvester, Linux, Malware, Microsoft Graph API, South Asia, Symantec, VirusTotal

Post navigation

Previous Post: Mastodon Faces Major DDoS Attack Following Bluesky Incident
Next Post: Rise in Supply Chain Attacks Highlights SBOM Challenges

Related Posts

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version The Hacker News
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog The Hacker News
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs The Hacker News
Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin The Hacker News
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries The Hacker News
6 Steps to 24/7 In-House SOC Success 6 Steps to 24/7 In-House SOC Success The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark