PULSE NAME
Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor
WHITE Harvester AlienVault 2026-05-01 Modified: 2026-05-04
16
IOCs
MEDIUM VOLUME
The Harvester APT group has developed a new Linux version of its GoGra backdoor that uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel. The malware employs social engineering lures with tailored decoy documents, masquerading malicious ELF files as standard documents. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The backdoor uses hardcoded Azure AD credentials to poll a specific mailbox folder at two-second intervals, executing commands received via encrypted emails and exfiltrating results through reply messages. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating Harvester's multi-platform development strategy and continued focus on South Asian espionage operations.
Indicators of Compromise (5 / 16 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 2d0177a00bed31f72b48965bee34cec04cb5be8eeea66ae0bb144f77e4d439b1 2026-05-01
FileHash-SHA256 57cd5721bae65c29e58121b5a9b00487a83b6c37dded56052cab2a67f90ea943 2026-05-01
FileHash-SHA256 74ac41406ce7a7aa992f68b4b3042f980027526f33ec6c8d84cb26f20495c9dc 2026-05-01
FileHash-SHA256 9c23c65a8a392a3fd885496a5ff2004252f1ad4388814b20e5459695280b0b82 2026-05-01
FileHash-SHA256 d8d84eaba9b902045ae4fe044e9761ad0ce9051b85feea3f1cf9c80b59b2b123 2026-05-01