SIESTAGRAPH is a Windows .NET backdoor used in espionage intrusions and associated with the REF2924 intrusion set, which targeted foreign affairs and telecommunications entities in Asia. It is notable for abusing Microsoft Graph API as a command-and-control channel, blending malicious activity with legitimate Microsoft 365 traffic. The malware interacts with Microsoft 365 Mail and OneDrive, using Outlook draft messages to exchange tasking and results and OneDrive for file transfer operations. Reporting has also linked it with PRC-affiliated activity and broader China-nexus intrusion clusters operating in sensitive government environments.
SIESTAGRAPH obtains Microsoft Graph access tokens using embedded authentication material and leverages a legitimate third-party OneDrive API library to communicate with Microsoft services. It creates a session identifier from host and process metadata, periodically polls for commands, and supports remote shell execution, configurable sleep intervals, file upload and download, drive and directory listing, file deletion and renaming, process enumeration and termination, network discovery, screenshot capture, and self-termination. Command output and host information are exfiltrated through Microsoft 365 mail drafts, while cloud-backed communications help the implant evade network-based detection by masquerading as normal enterprise SaaS usage.
The malware has been observed alongside other implants and access tools including DOORME, NAPLISTENER, SOMNIRECORD, SHADOWPAD, and COBALTSTRIKE in long-running compromises of diplomatic and telecommunications targets. It is part of a broader trend of state-linked malware families that use Microsoft Graph and OneDrive for covert command and control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SIESTAGRAPH is a .NET backdoor that leverages the Microsoft Graph interface, a collection of APIs for accessing various Microsoft services.
SIESTAGRAPH is a .NET backdoor that leverages the Microsoft Graph interface, a collection of APIs for accessing various Microsoft services.
We first observed this type of third-party C2 in SIESTAGRAPH, which we reported in December 2022.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The NET command gathers information about open TCP connections from the system's TCP table... This code helps the attacker to get a better insight into the system's purpose within the network.
We have identified the following commands... P Get a list of running processes.
After obtaining authentication and session tokens, the malware collects system information and exfiltrates it using a method called sendSession... A session token (sessionToken) is created by concatenating the process ID, machine name, username, and operating system.
SIESTAGRAPH interacts with Microsoft’s GraphAPI for command and control using Outlook and OneDrive... The implant utilizes the Microsoft Graph API to access Microsoft 365 Mail and OneDrive for its C2 communication.
Inspecting the sendSession method we see that it creates an email message and saves it as a draft. Using draft messages is common C2 tradecraft as a way to avoid email interception and inspection... the implant will use the getMessages method to check for any draft emails with commands from the attacker.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor mentioned for comparison that leverages the Microsoft Graph API to access Microsoft 365 Mail for command-and-control communication.
Previously reported malware family that similarly abuses Outlook mail service via the Microsoft Graph API for command-and-control (referenced as a technique comparison to FINALDRAFT).
Previously reported malware/campaign tooling noted for abusing Microsoft Graph API for command and control, referenced here as an earlier example of the same C2 technique.
Backdoor used in espionage intrusions that leverages the Microsoft Graph API to communicate through OneDrive and Microsoft 365 Mail for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.