Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor

May 4, 2026, 2:33 p.m.

Description

The Harvester APT group has developed a new Linux version of its GoGra backdoor that uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel. The malware employs social engineering lures with tailored decoy documents, masquerading malicious ELF files as standard documents. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The backdoor uses hardcoded Azure AD credentials to poll a specific mailbox folder at two-second intervals, executing commands received via encrypted emails and exfiltrating results through reply messages. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating Harvester's multi-platform development strategy and continued focus on South Asian espionage operations.

Date

  • Created: May 1, 2026, 5:53 p.m.
  • Published: May 1, 2026, 5:53 p.m.
  • Modified: May 4, 2026, 2:33 p.m.

Indicators

  • 9c23c65a8a392a3fd885496a5ff2004252f1ad4388814b20e5459695280b0b82
  • d8d84eaba9b902045ae4fe044e9761ad0ce9051b85feea3f1cf9c80b59b2b123
  • 2d0177a00bed31f72b48965bee34cec04cb5be8eeea66ae0bb144f77e4d439b1
  • 74ac41406ce7a7aa992f68b4b3042f980027526f33ec6c8d84cb26f20495c9dc
  • 57cd5721bae65c29e58121b5a9b00487a83b6c37dded56052cab2a67f90ea943

Attack Patterns

Additional Informations

  • India
  • British Indian Ocean Territory
  • Afghanistan