Microsoft Graph API
-
Webworm adds Discord and Microsoft Graph backdoors in new 2025 campaign
Webworm used new backdoors in 2025 that relied on Discord and Microsoft Graph API for command and control, according to an ESET technical analysis. The group also expanded its proxy tools and targeted government and enterprise networks in Asia and Europe.
-
Harvester deploys Linux version of GoGra backdoor in South Asia targeting campaign
Harvester has deployed a Linux version of its GoGra backdoor in attacks likely aimed at South Asia, using Microsoft cloud email services as a covert control channel, according to a technical analysis by Symantec and Carbon Black Threat Hunter Team.


