[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYNQYedPPMMSaZICvKxzJiz9j4KPOaakS4TagqWxFk9E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"c1f291f0-2f66-45c2-817e-e302974a796e","harvester-uses-disguised-files-and-microsoft-graph-api-for-covert-c2","e58e2118-1606-456b-a030-217c88f57802","Harvester Uses Disguised Files and Microsoft Graph API for Covert C2","The Harvester threat actor successfully deployed Linux malware by disguising ELF executables as PDF files, exploiting users' trust in document formats. The attack leveraged legitimate Microsoft Graph API and Outlook mailboxes as a command-and-control channel, allowing the malware to blend in with normal email traffic and bypass network security controls. This demonstrates how attackers can abuse legitimate cloud services and social engineering to establish persistent, hard-to-detect communication channels.","**Immediate actions:**\n- Implement file type validation to detect executables masquerading as documents\n- Monitor Microsoft Graph API usage for unusual patterns or unauthorized applications\n- Review email folder creation and naming conventions for suspicious activity\n\n**Long-term improvements:**\n- Deploy advanced email security solutions with behavioral analysis capabilities\n- Establish application whitelisting policies for Linux systems\n- Implement zero-trust principles for cloud service access and API usage\n\n**Detection measures:**\n- Monitor email subjects and folder names matching attack patterns (e.g., \"Input\", \"Output\")\n- Set up alerts for unusual OData queries or Graph API authentication events\n- Deploy endpoint detection tools capable of identifying suspicious process execution from disguised files",[12,13,14,15,16,17,18],"CIS Control 7","CIS Control 12","NIST AC-2","NIST AC-6","NIST SI-3","MITRE ATT&CK T1566.001","MITRE ATT&CK T1071.003","published","2026-04-23T07:09:29.776661+00:00","2026-04-23T07:09:29.652+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F04\u002Fharvester-deploys-linux-gogra-backdoor.html","harvester-deploys-linux-gogra-backdoor-in-south-asia-using-microsoft-graph-api-d04ed9","Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":34,"name":35,"slug":36,"description":37,"color":38},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]