Harvester Turns Outlook Into Stealth Linux Command Channel
Harvester is using Microsoft cloud services as command-and-control, which makes its traffic look like normal tenant activity instead of malware. The standard response of blocking suspicious domains misses the point here, because the backdoor lives inside Outlook mailbox access and can blend into legitimate Graph API use.
Symantec and Carbon Black say the Linux GoGra backdoor uses hardcoded Azure AD credentials to get OAuth tokens, then polls an Outlook mailbox folder called "Zomato Pizza" through Microsoft Graph API. The malware has been seen in artifacts from India and Afghanistan, and the campaign targets telecommunications, government, and IT organizations in South Asia.
The bigger risk is persistence inside environments that already trust Microsoft cloud traffic. Harvester has been active since at least 2021, and this Linux variant shows the group is expanding beyond Windows to reach more endpoints with the same covert channel.