PULSE NAME
Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor
WHITE Harvester AlienVault 2026-05-01 Modified: 2026-05-04
16
IOCs
MEDIUM VOLUME
The Harvester APT group has developed a new Linux version of its GoGra backdoor that uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel. The malware employs social engineering lures with tailored decoy documents, masquerading malicious ELF files as standard documents. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The backdoor uses hardcoded Azure AD credentials to poll a specific mailbox folder at two-second intervals, executing commands received via encrypted emails and exfiltrating results through reply messages. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating Harvester's multi-platform development strategy and continued focus on South Asian espionage operations.
Indicators of Compromise (5 / 16 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 4d9ae84166f2083a1ee7f3e7a0b3581e4b41bc4b 2026-05-01
FileHash-SHA1 7f58210fa9fb9a154a8c9b4d595f10c3ef7f79ec 2026-05-01
FileHash-SHA1 a225c68ddfaa81bc3f13bbfc65a85b4e047e8aa5 2026-05-01
FileHash-SHA1 afce743ccdd089a4132aad647ed47ba13b3f83b0 2026-05-01
FileHash-SHA1 c78c6f9b78e9503ab1a079010cf12a6182ec4d43 2026-05-01