Graphican is a backdoor malware family used by the China-linked espionage group APT15, also tracked as Nickel, Flea, Ke3Chang, and Vixen Panda. Symantec reported its use in a campaign observed from late 2022 to early 2023 targeting foreign affairs ministries in Central and South America, with other reporting describing the focus as foreign affairs ministries in the Americas. Graphican is described as an evolution of APT15’s older malware lineage, specifically Ketrican, which itself was based on BS2005.
Its distinguishing feature is the use of Microsoft Graph API and OneDrive to obtain command-and-control infrastructure in encrypted form, helping the operators blend with legitimate Microsoft cloud traffic and making takedowns more difficult. On infected systems, Graphican disables Internet Explorer 10 first-run and welcome settings via registry keys, checks for iexplore.exe, and creates an IWebBrowser2 COM object for internet access. It authenticates to Microsoft Graph to obtain access and refresh tokens, enumerates child files and folders in a OneDrive folder named "Person," and decrypts the first folder name to derive the C2 server address. It then generates a bot ID from host attributes including hostname, local IP, Windows version, default language identifier, and process bitness, registers with the C2, and polls for commands.
Reported capabilities include interactive command execution, remote file creation, file download to the C2, hidden process creation, and hidden PowerShell execution with output exfiltration. In the same APT15 campaign, Symantec also observed supporting tooling including EWSTEW for email theft from Exchange servers, credential dumping tools such as Mimikatz, Pypykatz, Safetykatz, Lazagne, Quarks PwDump, and SharpSecDump, web shells including AntSword, Behinder, China Chopper, and Godzilla, and use of an exploit for CVE-2020-1472. Reported initial access methods associated with APT15 include phishing emails, exploitation of vulnerable internet-exposed endpoints, and VPN-based access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"CVE-2020-1472 exploit – Elevation of privilege vulnerability affecting the Netlogon Remote Protocol."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Associated Malware & Tools graphon ... Graphican GoGra remsec_strider BirdyClient Grager graphite
In June 2023, Symantec discovered Backdoor.Graphican, which was being used by the Flea (aka APT15, Nickel) advanced persistent threat group in an espionage campaign heavily focused on foreign affairs ministries in the Americas.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Graphican is a backdoor malware used by APT15, leveraging the Microsoft Graph API for stealthy command and control.
Listed as an associated malware/tool used by the Harvester/APOPHIS activity, but the content provides no functional description.
Backdoor leveraging cloud services (per broader article theme) and used in campaigns attributed to Flea/APT15/Nickel.
Backdoor used by Flea that evolved from Ketrican and added Microsoft Graph API and OneDrive-based command-and-control capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.