Harvester is a likely nation-state-backed cyberespionage threat actor active since at least 2021. Symantec first documented the group in 2021 targeting organizations in South Asia, including the telecommunications, government, and information technology sectors. Reporting in the provided content also describes targeting in utilities, finance and insurance, healthcare and social assistance, public administration, telecommunications, and national security, with geographic references including South Asia, Afghanistan, Ukraine, Hong Kong, and the U.S. Virgin Islands; however, the strongest repeated reporting centers on South Asia, especially India and Afghanistan. Harvester is associated with custom backdoors including Graphon and GoGra. Graphon used Microsoft Graph API for command and control through Microsoft infrastructure. More recent reporting links Harvester to a Linux variant of GoGra, expanding a previously known Windows espionage toolset into a cross-platform capability. Symantec and the Carbon Black Threat Hunter Team linked the Linux malware to Harvester based on nearly identical code, shared command-and-control logic, shared AES usage, and matching coding mistakes. The group uses social engineering for initial access, including ELF binaries disguised as PDF documents and tailored decoy files such as Zomato- and Umrah-themed lures. The Linux GoGra malware establishes persistence via a systemd user unit and an XDG autostart entry masquerading as Conky. It contains hardcoded Azure AD credentials, requests OAuth2 tokens, and uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel. The malware polls mailbox folders for emails with subjects beginning with "Input," decrypts AES-CBC-encrypted tasking, executes commands via /bin/bash, returns encrypted results in emails with subject "Output," and deletes tasking messages afterward to reduce forensic traces. The content characterizes Harvester as an espionage-focused actor that uses both custom malware and publicly available tools and is actively expanding its tooling to target a wider range of systems, including Linux. Known aliases mentioned in the content include APOPHIS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage activity targeting Linux and previously Windows systems in South Asia using custom backdoors and Microsoft services as covert command-and-control infrastructure.
Espionage group active since at least 2021 targeting telecommunications, government, and IT organizations in South Asia using custom tools, including the GoGra backdoor delivered through Microsoft Outlook infrastructure via the Microsoft Graph API.
Espionage-focused activity in South Asia using a new Linux variant of the GoGra backdoor that abuses Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel.
Cyberespionage group expanding its cross-platform tooling with a Linux version of the GoGra backdoor that uses Microsoft Graph API and Outlook mailboxes as a covert C2 channel, with apparent targeting interest in South Asia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.