Harvester
Nation-state (South Asia nexus — India-assessed, not publicly attributed) · Espionage / intelligence collection
Tactics, Techniques & Procedures (TTPs)
- GoGra backdoor (Go-based) using Microsoft Outlook via Graph API as C2 relay — traffic indistinguishable from legitimate Microsoft 365 activity
- Linux-native GoGra variant (2026) extending targeting beyond Windows to server and telecoms infrastructure
- Backdoor.Graphon (Windows, custom) — predecessor implant with identical Graph API C2 design
- C2 via hardcoded Microsoft Entra ID application credentials polling a controlled Outlook mailbox folder
- Custom screenshot utilities and file staging tools alongside backdoor
- Targeting of government and telecoms back-end infrastructure with sustained multi-year persistence
Known Targets
Analyst Notes
First documented by Symantec in November 2021 following intrusion activity against Afghan entities coinciding with the final period of NATO presence. Attribution to a specific state has not been publicly made; South Asian nexus is assessed on the basis of targeting priorities. The group's defining technical signature — routing C2 through legitimate Microsoft cloud APIs — predates wider APT adoption of this technique, indicating early investment in cloud-infrastructure evasion. The April 2026 Linux variant extends operational reach to server environments (email servers, web infrastructure, telecoms back-ends) that typically run Linux and sit outside Windows-centric EDR coverage.
Also Known As