PULSE NAME
GoGra, Grager, and MoonTag: The Rise of Cloud-Based Cyber Threats
WHITE eric.ford 2024-08-12 Modified: 2024-09-11
41
IOCs
MEDIUM VOLUME
A recent Symantec blog post details how malicious actors are increasingly abusing legitimate cloud services like Microsoft Graph API and Google Drive for command and control (C2) and data exfiltration. Abusing trusted cloud services lets attackers blend malicious traffic with legitimate activity, making detection harder. This trend highlights the need for advanced security strategies and vigilance to protect sensitive data from evolving cyber threats and enhance cyber resiliency.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Grager GoGra MoonTag gdrive client Onedrivetools BirdyClient
Indicators of Compromise (14 / 41 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 30093c2502fed7b2b74597d06b91f57772f2ae50ac420bcaa627038af33a6982 2024-08-12
FileHash-SHA256 4057534799993a63f41502ec98181db0898d1d82df0d7902424a1899f8f7f9d2 2024-08-12
FileHash-SHA256 45a5dd715dc5f08f3b987a0415c2e500c549508aadf4183fdb94f749af8f1d67 2024-08-12
FileHash-SHA256 527fada7052b955ffa91df3b376cc58d387b39f2f44ebdcb54bc134e112a1c14 2024-08-12
FileHash-SHA256 582b21409ee32ffca853064598c5f72309247ad58640e96287bb806af3e7bede 2024-08-12
FileHash-SHA256 79e56dc69ca59b99f7ebf90a863f5351570e3709ead07fe250f31349d43391e6 2024-08-12
FileHash-SHA256 97551bd3ff8357831dc2b6d9e152c8968d9ce1cd0090b9683c38ea52c2457824 2024-08-12
FileHash-SHA256 9f61ed14660d8f85d606605d1c4c23849bd7a05afd02444c3b33e3af591cfdc9 2024-08-12
FileHash-SHA256 a76507b51d84708c02ca2bd5a5775c47096bc740c9f7989afd6f34825edfcba6 2024-08-12
FileHash-SHA256 ab6a684146cec59ec3a906d9e018b318fb6452586e8ec8b4e37160bcb4adc985 2024-08-12
FileHash-SHA256 d728cdcf62b497362a1ba9dbaac5e442cebe86145734410212d323a6c2959f0f 2024-08-12
FileHash-SHA256 f1ccd604fcdc0034d94e575b3709cd124e13389bbee55c59cbbf7d4f3476e214 2024-08-12
FileHash-SHA256 f69fb19604362c5e945d8671ce1f63bb1b819256f51568daff6fed6b5cc2f274 2024-08-12
FileHash-SHA256 fd9fc13dbd39f920c52fbc917d6c9ce0a28e0d049812189f1bb887486caedbeb 2024-08-12