SiestaGraph is a Windows .NET backdoor used by the REF2924 intrusion set. It abuses the Microsoft Graph API to use Microsoft 365 Mail and OneDrive as command-and-control and file-transfer infrastructure. The implant obtains Graph access tokens using embedded OAuth material, identifies hosts using system-derived session information, sends session data and command results through Outlook draft messages, and polls for operator commands at a configurable interval. Its capabilities include command execution through the Windows command interpreter; drive, directory, file, process, and network-connection enumeration; process termination; file deletion and renaming; OneDrive-based file upload and download; screenshot capture; and self-termination. Graph-based communications can blend with legitimate Microsoft 365 traffic and complicate network-only detection. SiestaGraph was used in espionage activity targeting the foreign-affairs organization of an ASEAN member state. REF2924 has been assessed with moderate confidence to be associated with a regionally aligned, non-monetary threat group, with reported operational overlaps involving activity tracked as Winnti and ChamelGang.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SIESTAGRAPH is a .NET backdoor that leverages the Microsoft Graph interface, a collection of APIs for accessing various Microsoft services.
SIESTAGRAPH is a .NET backdoor that leverages the Microsoft Graph interface, a collection of APIs for accessing various Microsoft services.
This environment has already seen the emergence of the REF2924 intrusion set (SIESTAGRAPH, NAPLISTENER, SOMNIRECORD, and DOORME).
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The executable renamed itself svchost.exe before installing itself as a service.
The NET command gathers information about open TCP connections from the system's TCP table... This code helps the attacker to get a better insight into the system's purpose within the network.
The NET command gathers information about open TCP connections from the system's TCP table.
After obtaining authentication and session tokens, the malware collects system information and exfiltrates it using a method called sendSession... A session token (sessionToken) is created by concatenating the process ID, machine name, username, and operating system.
SIESTAGRAPH interacts with Microsoft’s GraphAPI for command and control using Outlook and OneDrive... The implant utilizes the Microsoft Graph API to access Microsoft 365 Mail and OneDrive for its C2 communication.
SIESTAGRAPH... uses the Microsoft Graph API to access Microsoft 365 Mail and OneDrive for its C2 communication.
Inspecting the sendSession method we see that it creates an email message and saves it as a draft. Using draft messages is common C2 tradecraft as a way to avoid email interception and inspection... the implant will use the getMessages method to check for any draft emails with commands from the attacker.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor mentioned for comparison that leverages the Microsoft Graph API to access Microsoft 365 Mail for command-and-control communication.
Previously reported malware family that similarly abuses Outlook mail service via the Microsoft Graph API for command-and-control (referenced as a technique comparison to FINALDRAFT).
Previously reported malware/campaign tooling noted for abusing Microsoft Graph API for command and control, referenced here as an earlier example of the same C2 technique.
Previously reported malware associated with abuse of Microsoft's Graph API for command-and-control communications. It is mentioned as a comparison to FINALDRAFT's Graph API C2 technique.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.