PULSE NAME
Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor
WHITE Harvester AlienVault 2026-05-01 Modified: 2026-05-04
16
IOCs
MEDIUM VOLUME
The Harvester APT group has developed a new Linux version of its GoGra backdoor that uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel. The malware employs social engineering lures with tailored decoy documents, masquerading malicious ELF files as standard documents. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The backdoor uses hardcoded Azure AD credentials to poll a specific mailbox folder at two-second intervals, executing commands received via encrypted emails and exfiltrating results through reply messages. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating Harvester's multi-platform development strategy and continued focus on South Asian espionage operations.
Indicators of Compromise (6 / 16 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1e8a11249ac38ca948a10308cc333a47 2026-05-01
FileHash-MD5 7bf2191620c2cca5f8238834149ba470 2026-05-01
FileHash-MD5 8f1af2175403195726957dc58fe64821 2026-05-01
FileHash-MD5 abfe90bd06b0781a075ed23757822816 2026-05-01
FileHash-MD5 b14ca5898a4e4133bbce2ea2315a1916 2026-05-01
FileHash-MD5 d69cc848443b63eb0ae8d05a6ecfba5e 2026-05-01