Threats · 145 days ago
Harvester is using Microsoft cloud services as command-and-control, which makes its traffic look like normal tenant activity instead of malware. The standard response of blocking suspicious domains misses the point here, because the backdoor lives inside Outlook mailbox access and can blend into legitimate Graph API use.
Symantec and Carbon Black say the Linux GoGra backdoor uses hardcoded Azure AD credentials to get OAuth tokens, then polls an Outlook mailbox folder called "Zomato Pizza" through Microsoft Graph API. The malware has been seen in artifacts from India and Afghanistan, and the campaign targets telecommunications, government, and IT organizations in South Asia.
The bigger risk is persistence inside environments that already trust Microsoft cloud traffic. Harvester has been active since at least 2021, and this Linux variant shows the group is expanding beyond Windows to reach more endpoints with the same covert channel.
2 sources covering this story
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
Harvester deploys Linux GoGra via Microsoft Graph API in South Asia, targeting India and Afghanistan since 2021, enabling covert espionage
New GoGra malware for Linux uses Microsoft Graph API for comms
A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery.
Part of the PlainSec briefing for 2026-04-22